Skip to content

bifroest key import ca

Validates and atomically merges plain OpenSSH certificate-authority public keys. Certificates, private keys, and authorized-key options are rejected. Concurrent merge operations are locked, and any fingerprint mismatch leaves the destination unchanged.

Syntax

bifroest key import ca [flags]

Flags

Includes all general flags.

--trustedCAsFile

Public-key file containing the trusted SSH certificate authorities to update.

--input

File Path = "-"

File containing the public CA keys. - reads from stdin.

--expectedFingerprint

string

Expected OpenSSH SHA256 fingerprint of every imported CA, or unknown. Omission implies unknown.

Example

See Bifröst delegation authorization for a complete CA exchange.