{"repo":"prodnull/prmana","free":true,"listed":false,"github":"https://github.com/prodnull/prmana","clone":"git clone https://github.com/prodnull/prmana.git","description":"OIDC SSH login for Linux with DPoP — replace static SSH keys with IdP-issued tokens, no gateway","language":"Rust","stars":24,"topics":["authentication","dpop","linux","oidc","pam","security","ssh"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"prmana OIDC SSH login for Linux, without the gateway Replace static SSH keys with short-lived IdP-issued tokens, validated directly at the host through PAM, without requiring a gateway or SSH certificate authority. Why? &bull; How It Works &bull; Quick Start &bull; Documentation &bull; Contributing --- Why prmana? SSH keys get copied, shared, and never rotated. When someone leaves, finding all their access is archaeology. Corporate MFA stops at the browser — you need it for email but not for root on production. prmana bridges this gap by bringing OIDC (the same protocol behind \"Sign in with Google/Microsoft/Okta\") to Linux PAM, with DPoP token binding to prevent token theft. Why teams try it - Kill static SSH keys without forcing a full access platform rollout - Keep direct-to-host SSH instead of routing everything through a proxy - Reuse your existing IdP (Keycloak, Okta, Azure AD, Auth0, Google) for Linux login - Get proof-of-possession with DPoP — not just bearer-token login - Stay Linux-native with PAM at the host boundary - Start small on a few hosts before deciding whether you need more What makes it different Most alternatives fall into one of three buckets: - Access platforms that introduce a proxy, gateway, or managed control plane - SSH certificate systems that add a CA and cert lifecycle layer - Simpler PAM/OIDC modules that provide SSO but not strong proof-of-possession prmana takes a different path: OIDC-backed login directly at the Linux host, with DPoP-bound au","default_branch":null,"files":null,"tree":[],"storefront":"/r/prodnull","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/prodnull/prmana/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}