peleg — personal SSH host CA ============================ Mints OpenSSH HOST certificates so SSH clients trust servers signed by this CA without TOFU prompts ("Are you sure you want to continue connecting?"). The Go twin of the bildad Cloudflare Worker; both sign with the same CA key, so their certificates are interchangeable. All endpoints are unauthenticated and respond with text/plain. Certificates: 10-year validity, key_id = the principals joined with commas. ENDPOINTS --------- POST /sign Sign a host public key. Request body: a JSON object. public_key string REQUIRED the host's public key in OpenSSH authorized_keys format — the contents of /etc/ssh/ssh_host_ed25519_key.pub principals [string] REQUIRED hostnames (FQDNs) the certificate is valid for — the names clients type after "ssh" Response: 200 — one OpenSSH host-certificate line. Save it next to the host key as /etc/ssh/ssh_host_ed25519_key-cert.pub (mode 0644). Errors: 400 — bad JSON, missing fields, or unparseable public_key. GET /ca.pub The CA public key in authorized_keys format. Compare against the twin service's /ca.pub to confirm both serve the same CA. GET /known-hosts?pattern= A known_hosts "@cert-authority" line trusting this CA for hosts matching . Append it to ~/.ssh/known_hosts. pattern string OPTIONAL host glob (default "*"), e.g. *.eick.com GET /help This document (also served at /). EXAMPLES -------- # 1. Full host-signing flow — run on the server being signed (needs jq): curl -sS -X POST https://peleg.spouterinn.org/sign \ -H 'content-type: application/json' \ -d "$(jq -n \ --arg k "$(cat /etc/ssh/ssh_host_ed25519_key.pub)" \ --arg p "$(hostname -f)" \ '{public_key:$k, principals:[$p]}')" \ | sudo tee /etc/ssh/ssh_host_ed25519_key-cert.pub > /dev/null # ...the same without jq: curl -sS -X POST https://peleg.spouterinn.org/sign \ -H 'content-type: application/json' \ --data "{\"public_key\":\"$(cat /etc/ssh/ssh_host_ed25519_key.pub)\",\"principals\":[\"$(hostname -f)\"]}" \ | sudo tee /etc/ssh/ssh_host_ed25519_key-cert.pub > /dev/null # 2. Sign for several principals (every name clients might connect with): curl -sS -X POST https://peleg.spouterinn.org/sign \ -H 'content-type: application/json' \ --data '{"public_key":"ssh-ed25519 AAAAC3... root@host","principals":["host.eick.com","host","10.0.0.5"]}' # 3. Inspect the certificate you got back: ssh-keygen -L -f /etc/ssh/ssh_host_ed25519_key-cert.pub # 4. Tell sshd to present it, then validate and reload: echo 'HostCertificate /etc/ssh/ssh_host_ed25519_key-cert.pub' \ | sudo tee /etc/ssh/sshd_config.d/10-host-cert.conf sudo sshd -t && sudo systemctl reload ssh # 5. Fetch the CA public key: curl -sS https://peleg.spouterinn.org/ca.pub # 6. Trust the CA on a client, scoped to one domain (quote the URL — the * # must reach the server, not the shell): curl -sS 'https://peleg.spouterinn.org/known-hosts?pattern=*.eick.com' >> ~/.ssh/known_hosts