<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Pki on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/pki/</link>
    <description>Recent content in Pki on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/pki/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SSH Logins Signed By step-ca: No More authorized_keys</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-ssh-certificates/</link>
      <pubDate>Fri, 09 Oct 2026 18:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-ssh-certificates/</guid>
      <description>Using step-ca as an SSH certificate authority: signing host keys so clients stop asking to trust them, signing user keys so servers need no authorized_keys, the two sshd_config lines and one known_hosts line it takes, what was refused in testing, and renewing host certificates.</description>
    </item>
    <item>
      <title>Client Certificates From step-ca, And The Defaults That Lock Everyone Out</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</link>
      <pubDate>Fri, 09 Oct 2026 18:20:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</guid>
      <description>Using step-ca to issue client certificates for mTLS, tested with nginx and Caddy. The 24-hour limit and how to raise it, a CRL that rejects everyone until its scope is fixed, the root CRL nginx needs, publishing CRLs over HTTP, the refresh job that stops them lapsing, and the PKCS12 file and CA certificates a phone needs.</description>
    </item>
    <item>
      <title>Your Own Certificate Authority: step-ca In A Container</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-in-a-container/</link>
      <pubDate>Fri, 09 Oct 2026 17:50:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-in-a-container/</guid>
      <description>Smallstep&amp;#39;s step-ca in a Podman or Docker container as the certificate authority for everything inside the house: why it beats self-signed and public certificates for internal names, the two passwords the image makes, trusting the root, internal HTTPS over ACME, and renewing services that cannot do ACME.</description>
    </item>
  </channel>
</rss>
