SSH CA certs in Satellite
Issue
By default, Satellite uses SSH keys when connecting to remote hosts for remote execution. Each Capsule has its own keypair and uses its private key when connecting to remote hosts. When hosts are registered to Satellite or provisioned from Satellite, Capsules' public keys are deployed to them, thus granting access. At the same time, each host has its own set of host keys that it presents when clients connect to it.
An alternative to this is the use of CA-signed SSH certificates. Satellite doesn't provide any facilities for this, but if SSH certificates are placed into the right places, Satellite can use them.
Environment
Satellite 6.14 and newer
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.