1. SSH Secrets Engine Overview
SSH Secrets Engine solves the problem of managing SSH access in enterprises. Instead of distributing SSH keys manually (and never revoke), Vault provides two mechanisms:
| Mode | How it works | Recommendation |
|---|---|---|
| Signed Certificates (CA) | Vault sign SSH public key → short-term certificate | ✅ Recommended |
| OTP | Vault generates one-time password to SSH | Legacy, needs vault-ssh-helper |
2. SSH CA Mode (Signed Certificates)
Architecture
┌──────────┐ 1. Sign my key ┌──────────────┐
│ User │ ───────────────────▶ │ Vault │
│ │ │ SSH CA │
│ │ 2. SSH Certificate │ │
│ │ ◀─────────────────── │ │
│ │ └──────────────┘
│ │
│ │ 3. SSH with certificate
│ │ ───────────────────▶ ┌──────────────┐
│ │ │ Server │
│ │ 4. Verify cert │ (trusts CA) │
│ │ against CA │ │
└──────────┘ └──────────────┘
Setup SSH CA
# Enable SSH secrets engine
vault secrets enable -path=ssh-client-signer ssh
# Sinh CA key pair (hoặc import existing)
vault write ssh-client-signer/config/ca generate_signing_key=true
# Lấy CA public key
vault read -field=public_key ssh-client-signer/config/ca > /etc/ssh/trusted-user-ca-keys.pem
Configure SSH Server to trust Vault CA
# Trên mỗi SSH server — thêm vào /etc/ssh/sshd_config
TrustedUserCAKeys /etc/ssh/trusted-user-ca-keys.pem
# Restart sshd
sudo systemctl restart sshd
Create roles
# Role cho developers — SSH vào dev servers
vault write ssh-client-signer/roles/dev-ssh \
key_type=ca \
default_user=developer \
allowed_users="developer,deploy" \
allowed_extensions="permit-pty,permit-port-forwarding" \
default_extensions='{"permit-pty": ""}' \
ttl=8h \
max_ttl=24h \
allow_user_certificates=true \
algorithm_signer=rsa-sha2-256
# Role cho admin — SSH vào mọi server
vault write ssh-client-signer/roles/admin-ssh \
key_type=ca \
default_user=admin \
allowed_users="admin,root,ubuntu" \
allowed_extensions="permit-pty,permit-port-forwarding,permit-agent-forwarding" \
default_extensions='{"permit-pty": ""}' \
ttl=2h \
max_ttl=8h \
allow_user_certificates=true
Sign SSH key
# Sinh SSH key pair nếu chưa có
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519 -N ""
# Sign public key
vault write -field=signed_key ssh-client-signer/sign/dev-ssh \
public_key=@$HOME/.ssh/id_ed25519.pub \
valid_principals="developer" \
ttl=8h > ~/.ssh/id_ed25519-cert.pub
# Kiểm tra certificate
ssh-keygen -L -f ~/.ssh/id_ed25519-cert.pub
# SSH với certificate
ssh -i ~/.ssh/id_ed25519 [email protected]
Host Key Signing
# Enable SSH engine cho host keys
vault secrets enable -path=ssh-host-signer ssh
# Sinh host CA
vault write ssh-host-signer/config/ca generate_signing_key=true
# Tạo host role
vault write ssh-host-signer/roles/host-cert \
key_type=ca \
ttl=87600h \
allow_host_certificates=true \
allowed_domains="company.com,internal.company.com" \
allow_subdomains=true
# Sign host key
vault write -field=signed_key ssh-host-signer/sign/host-cert \
cert_type=host \
public_key=@/etc/ssh/ssh_host_ed25519_key.pub \
valid_principals="server1.company.com" \
> /etc/ssh/ssh_host_ed25519_key-cert.pub
# Cấu hình server sử dụng host certificate
# /etc/ssh/sshd_config
# HostCertificate /etc/ssh/ssh_host_ed25519_key-cert.pub
3. SSH OTP Mode
# Enable
vault secrets enable -path=ssh-otp ssh
# Tạo role
vault write ssh-otp/roles/otp-role \
key_type=otp \
default_user=ubuntu \
cidr_list="10.0.0.0/8"
# Sinh OTP
vault write ssh-otp/creds/otp-role \
ip=10.0.1.50 \
username=ubuntu
# key: 1a2b3c4d-5e6f-7g8h
# SSH với OTP
ssh [email protected]
# Password: 1a2b3c4d-5e6f-7g8h (one-time use)
Note: OTP mode requires installing vault-ssh-helper on the target server to verify OTP with Vault. CA mode does not require any additional settings on the server.
4. TOTP Secrets Engine
TOTP Secrets Engine allows Vault to generate and validate TOTP (Time-based One-Time Password) codes according to RFC 6238.
TOTP Generator Mode
# Enable TOTP
vault secrets enable totp
# Tạo key từ URL (khi setup 2FA cho service)
vault write totp/keys/github \
url="otpauth://totp/GitHub:john.doe?secret=JBSWY3DPEHPK3PXP&issuer=GitHub"
# Hoặc tạo key thủ công
vault write totp/keys/aws-console \
generate=true \
issuer="AWS" \
account_name="[email protected]" \
period=30 \
digits=6 \
algorithm=SHA1
# Sinh TOTP code
vault read totp/code/github
# code: 123456
# Validate code
vault write totp/code/github code=123456
# valid: true
Use case: Centralized 2FA Management
Instead of each employee managing 2FA codes on their individual phones, Vault can be a central storage place for TOTP keys — allowing for team rotation and not losing codes when changing phones.
5. LDAP Secrets Engine
LDAP Secrets Engine (different from LDAP Auth Method) generates dynamic LDAP credentials — creates and manages LDAP service accounts automatically.
# Enable LDAP secrets engine
vault secrets enable ldap
# Cấu hình kết nối
vault write ldap/config \
binddn="cn=admin,dc=company,dc=com" \
bindpass="adminpassword" \
url="ldaps://ldap.company.com" \
schema="openldap"
# Tạo dynamic role
vault write ldap/role/dynamic-svc \
[email protected] \
[email protected] \
[email protected] \
default_ttl=1h \
max_ttl=24h
# Tạo static role (password rotation)
vault write ldap/static-role/svc-account \
dn="cn=svc-app,ou=services,dc=company,dc=com" \
username="svc-app" \
rotation_period=24h
# Lấy dynamic credentials
vault read ldap/creds/dynamic-svc
RACF Passphrase Support (Vault 1.21)
Vault 1.21 adds support for RACF passphrases to mainframe environments — allowing passphrases longer than the traditional 8 characters:
vault write ldap/config \
schema="racf" \
password_policy="racf-passphrase-policy"
6. Summary
SSH CA Mode — recommended, short-term sign certificates, no agent required on server
SSH OTP Mode — one-time passwords, requires vault-ssh-helper
TOTP Engine — sinh/validate TOTP codes, centralized 2FA management
LDAP Secrets Engine — dynamic LDAP credentials, static role rotation
RACF Passphrase (1.21) — mainframe environments support
The next article will explore Transform and Tokenization — data protection for PCI DSS, PII, and compliance requirements.