Releases: zeroSteiner/ssh-ca
Release list
v0.2.0: Cloning Support
This release adds support for cloning a previously initialized YubiKey to a new one.
Cloning
Given an existing YubiKey that was already initialized and the age-encrypted CA private key data, a new YubiKey can be initialized using the clone command. This new YubiKey can be used in the future to initialize new ones as well. A new age-encrypted CA private key will be generated for all of the YubiKey recipients, both old and new.
Database Schema
In order to support cloning YubiKeys and maintaining backwards compatibility with all previously cloned YubiKeys, the database was updated to track recipient information for previously initialized CA files. This is necessary to include the old recipients for newly encrypted CA files. The database now also includes schema tracking. A new database command with schema and upgrade subcommands is now available for seeing the current schema, and for upgrading to the latest schema.