HomeSecurityCloudflare announces OpenPubkey SSH

Cloudflare announces OpenPubkey SSH

Cloudflare announced the open availability of OPKSSH (OpenPubkey SSH) on March 25, 2025.This technology combines single sign-on (SSO) with SSH authentication, eliminating the need for manual SSH key management.

See also: Cloudflare blocked DDoS attack that peaked at 5.6 Tbps

Cloudflare OpenPubkey SSH

The code, previously owned by BastionZero (which was acquired by Cloudflare), has been donated to the OpenPubkey project under the Apache 2.0. The announcement represents a significant advancement in secure remote access technology.

OPKSSH is an implementation of the OpenPubkey protocol, designed specifically for SSH authentication. It leverages OpenID Connect (OIDC), the leading protocol for single sign-on (SSO), allowing users to authenticate through Identity Providers (IdPs) such as Google, Azure, or Okta.

CloudFlare’s OpenPubkey SSH extends standard OIDC ID Tokens by adding a user’s public key, creating what’s called a PK Token. This essentially turns the ID Token into a certificate that states, for example, “Google confirms that alice@example.com uses the public key 0x123.”

OPKSSH then allows these PK Tokens to act as SSH keys in standard SSH, adding SSO authentication without modifying SSH itself.

See also: Cloudflare's developer domains are being abused by hackers

The beauty of this approach is that it works with any OpenID Connect-, without requiring changes to existing SSO protocols.

Cloudflare announces OpenPubkey SSH
Cloudflare announces OpenPubkey SSH

Traditional SSH relies on long-term public-private key pairs, which create significant security and management challenges.

According to SSH inventor Tatu Ylonen, “in many organizations, there are many times more outdated authorized_keys than there are employees.”

These keys never expire, creating a permanent risk. Studies show that weak or default SSH credentials cause 30% of SSH-related security incidents.

Organizations face difficulties in tracking keys across systems, managing access when employees leave, and preventing unauthorized access through compromised keys. The over-proliferation of SSH keys causes additional management overhead, operational complexity, and compliance challenges with regulations such as PCI-DSS and GDPR.

See also: Cloudflare: Lost 55% of logs for 3.5 hours

SSH (Secure Shell) authentication is a process that allows for secure connection and communication with remote computers over a network. SSH is primarily used to allow users to connect to remote systems and execute commands or manage files in a secure manner. SSH key authentication is considered more secure and widely recommended, as it is more difficult to crack than passwords.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS