certificates VS pam-ussh

Compare certificates vs pam-ussh and see what are their differences.

certificates

🛡️ A private certificate authority (X.509 & SSH) & ACME server for secure automated certificate management, so you can use TLS everywhere & SSO for SSH. (by smallstep)

pam-ussh

uber's ssh certificate pam module (by uber)
Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
certificates pam-ussh
40 3
6,154 827
3.0% 0.1%
9.5 0.0
6 days ago about 1 year ago
Go Go
Apache License 2.0 MIT License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

certificates

Posts with mentions or reviews of certificates. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2024-01-04.

pam-ussh

Posts with mentions or reviews of pam-ussh. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2020-11-03.
  • Sudo rules when using SSH certificates
    1 project | /r/devops | 30 Mar 2022
    One solution could be uber-pamussh which allows to reuse the SSH certificate and the given principals as filter for sudo access. Sounds great and works pretty god, but the issue is that the repo is not maintained (or has at least a low activity) which makes me doubt if this is a good solution.
  • Locking Down SSH - The Right Way
    1 project | /r/linux | 15 Oct 2021
    Yep. We're using Vault to provide SSH certs, and it works like a dream. For certain servers, we're even using this PAM module to provide passwordless sudo: https://github.com/uber/pam-ussh
  • Why SSH certificates are awesome
    7 projects | dev.to | 3 Nov 2020
    Uber’s PAM module

What are some alternatives?

When comparing certificates and pam-ussh you can also consider the following projects:

mkcert - A simple zero-config tool to make locally trusted development certificates with any names you'd like.

sshrimp - 🦐SSH Certificate Authority in a Lambda (on the barbie)

boulder - An ACME-based certificate authority, written in Go.

cashier - A self-service CA for OpenSSH

omgwtfssl - SSL certificate generation for developers who don't TLS good

bless - Repository for BLESS, an SSH Certificate Authority that runs as a AWS Lambda function

cfssl - CFSSL: Cloudflare's PKI and TLS toolkit

easy-rsa - easy-rsa - Simple shell based CA utility

traefik-certs-dumper - Dump ACME data from Traefik to certificates

dehydrated - letsencrypt/acme client implemented as a shell-script – just add water

keymaster - Short term certificate based identity system (ssh/x509 ca + openidc)

letsdane - 🔒 Let's DANE is an experimental way to enable the use of DANE/TLSA in browsers and other apps using a lightweight proxy.