The current job-signing key is named UNTRUSTED Support Shell Prototype, living in the sandbox OSS deployment. We need a production key and a certificate for it. Eventually we'd like an intermediate signed by Oxide's offline root, but for now, a self-signed cert for a permslip/KMS hosted key should be sufficient.
This issue must be closed before sush may be merged into Omicron; see oxidecomputer/omicron#11034.
The current job-signing key is named
UNTRUSTED Support Shell Prototype, living in the sandbox OSS deployment. We need a production key and a certificate for it. Eventually we'd like an intermediate signed by Oxide's offline root, but for now, a self-signed cert for a permslip/KMS hosted key should be sufficient.This issue must be closed before sush may be merged into Omicron; see oxidecomputer/omicron#11034.