Skip to content

bifroest key export ca

Loads the same configuration as bifroest run and exports the effective SSH certificate authority of the selected flow. If the private CA does not exist, it is generated before its public key is exported. No .pub companion file is created.

Syntax

bifroest key export ca [flags] <flowName>

Arguments

flowName is the name of an SSH-environment flow with certificate authentication enabled.

Flags

Includes all general flags.

--configuration

Configuration to load. The default is /etc/engity/bifroest/configuration.yaml on Linux, /Library/Application Support/Engity/Bifroest/configuration.yaml on macOS and C:\ProgramData\Engity\Bifroest\configuration.yaml on Windows.

--output

File Path = "-"

Output file. - writes exactly one LF-terminated OpenSSH public-key line to stdout.

--force

bool = false

Replaces an existing output file.

Examples

See the certificate-authentication examples for SSH environments and Bifröst delegation.