cloudflare / cloudflare/cloudflared

💡 Add option to SSH CA to issue certs with UserPrincipal with full e-mail address

Open
#1,122 0 comments 0 reactions 0 assignees View on GitHub
Priority: Normal Type: Feature Request
Dominant language
Go
Stars
15.6k
Forks
1.4k
PR merge metrics
No merged PRs in 30d

Description

**Describe the feature you'd like**
I would like an option in the SSH Short-Lived Certificates CA settings to sign certs with the full e-mail address of the user as the User Principal

The SSH CA currently signs certificates with the User Principal being the part of the e-mail address before the @ sign. Therefore, an access organization with multiple domains (i.e. using pin based auth with external collaborators) can have namespace conflicts when deciding which user to log in as.

Example: These users map to the same unix username.
```
jdoe@mycorp.com -> jdoe
jdoe@external.com -> jdoe
```

**Describe alternatives you've considered**
Unknown, this is not mentioned in the docs.

**Additional context**

https://developers.cloudflare.com/cloudflare-one/identity/users/short-lived-certificates/

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.