keys: optional expiry for SSH and deploy keys #277

closed cmc opened this on 2026-09-28 04:33 UTC · keys security

Discussion

cmc 2026-09-28 04:33 UTC

SSH user keys and deploy keys have no expiry (ssh_keys has no expiry column). A key added years ago keeps full access until someone removes it.

  • Optional --ttl on keys add and repo deploy-key add, enforced at authentication.
  • keys list shows last used, so stale keys are visible.
  • Consider with #257, which bounds credentials created by expiring tokens.

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

referenced in commit 253e1a2c23 by cmc: token: create refuses a zero or negative --ttl

2026-09-28 21:49 UTC

referenced in commit a8ba660761 by cmc: sshd: an expired key counts against the auth limiter

2026-09-28 21:49 UTC

referenced in commit 32a5f76e5b by cmc: control: key lists fit 60 columns; headers clip with their column

2026-09-28 21:49 UTC

referenced in commit 03040d2164 by cmc: control: keys add refuses --ttl 0h and negative

2026-09-28 21:49 UTC

closed by cmc in commit 1ed9fb9399: wiki: key expiry

2026-09-28 21:49 UTC

referenced in commit 44e5fb3a83 by cmc: keys: --ttl on keys add and repo deploy-key add; lists show last use and expiry

2026-09-28 21:49 UTC

referenced in commit 7f5c45d0af by cmc: sshd: refuse expired keys at auth and per exec; expiring keys cannot mint

2026-09-28 21:49 UTC

referenced in commit cab50f5004 by cmc: store: ssh_keys.expires_at; expired keys are not live

2026-09-28 21:49 UTC