mirror of
https://github.com/Termix-SSH/Termix.git
synced 2026-10-09 21:32:38 +00:00
# Conflicts: # package-lock.json # package.json # plugins/ai/locales/translated/af_ZA.json # plugins/ai/locales/translated/ar_SA.json # plugins/ai/locales/translated/bg_BG.json # plugins/ai/locales/translated/bn_BD.json # plugins/ai/locales/translated/ca_ES.json # plugins/ai/locales/translated/cs_CZ.json # plugins/ai/locales/translated/da_DK.json # plugins/ai/locales/translated/de_DE.json # plugins/ai/locales/translated/el_GR.json # plugins/ai/locales/translated/es_ES.json # plugins/ai/locales/translated/fi_FI.json # plugins/ai/locales/translated/fr_FR.json # plugins/ai/locales/translated/he_IL.json # plugins/ai/locales/translated/hi_IN.json # plugins/ai/locales/translated/hu_HU.json # plugins/ai/locales/translated/id_ID.json # plugins/ai/locales/translated/it_IT.json # plugins/ai/locales/translated/ja_JP.json # plugins/ai/locales/translated/ko_KR.json # plugins/ai/locales/translated/nl_NL.json # plugins/ai/locales/translated/no_NO.json # plugins/ai/locales/translated/pl_PL.json # plugins/ai/locales/translated/pt_BR.json # plugins/ai/locales/translated/pt_PT.json # plugins/ai/locales/translated/ro_RO.json # plugins/ai/locales/translated/ru_RU.json # plugins/ai/locales/translated/sr_SP.json # plugins/ai/locales/translated/sv_SE.json # plugins/ai/locales/translated/th_TH.json # plugins/ai/locales/translated/tr_TR.json # plugins/ai/locales/translated/uk_UA.json # plugins/ai/locales/translated/vi_VN.json # plugins/ai/locales/translated/zh_TW.json
Termix Identity
Publish your SSH public keys under a public handle and run your own SSH certificate authority.
Features
- Claim a public handle and publish your SSH public keys under it.
- Run your own SSH certificate authority for each handle.
- Issue short-lived certificates for your Ed25519 keys.
Setup
Any server can pull your keys into authorized_keys:
curl -fsSL https://<termix>/plugin-api/termix-identity/u/<handle> >> ~/.ssh/authorized_keys
Add /<ALGO>, for example /ED25519, to get only one key type. This URL needs no login and is never cached.
To use the certificate authority, point TrustedUserCAKeys on your servers at the public key from /u/<handle>/ca. Rotating the CA revokes every certificate it issued. Certificates are downloaded once and not stored, so Termix hosts do not use them to connect.
The 2.8 URLs under /termix-id/u/ redirect here, so existing scripts keep working. Use curl -L to follow the redirect.
Permissions
termix-identity.use: Claim a handle, publish keys and run a CA. Admins and users have it by default.
Development
npm run build # build into dist/
npm run test # run this plugin's tests
npm run typecheck # type-check this plugin