feat: v1.10.2, improve ssh-piv-cert

This commit is contained in:
2024-09-07 08:34:50 +08:00
parent 6f2d4d2369
commit 135631df90
4 changed files with 71 additions and 32 deletions

View File

@@ -173,6 +173,19 @@ $ card-cli pgp-age-address
[OK ] Age address: age10l464vxcpnkjguctvylnmp5jg4swhncn4quda0qxta3ud8pycc0qeaj2te
```
# sign-jwt
Sign a JWT:
```shell
card-cli sign-jwt -s r3 \
-C iss:****** \
-C sub:****** \
-C aud:client_gard****** \
-K KEY=ID \
--jti \
--validity 10m --json
```
# SSH CA
## Generate SSH root CA
@@ -196,6 +209,11 @@ ssh-keygen -f id_user
card-cli ssh-piv-cert --pub id_user.pub -s r15
```
Show SSH CA cert details:
```shell
ssh-keygen -L -f id_user-cert.pub
```
SSH to server:
```shell
ssh -i id_user root@example.com