SSH Key Lifecycle Management

Manage SSH keys before they become a breach.

Discover, rotate, and secure every SSH key across your infrastructure. Eliminate orphaned keys, detect privilege escalation paths, and enforce rotation policies at scale.

bash — tigertrust-ssh
Last login: Thu Aug 28 09:14:02 on ttyd002
admin@tiger:~$ssh admin@prod-01
Welcome to prod-01 · TigerTrust SSH Gateway
Certificate auth · expires 8h
admin@prod-01:~$
Key Rotation
ed25519 · 4096-bit RSA
Retiring
SHA256:3f2a89b1…
SHA256:c9d1fe42…
SHA256:a7b38c01…
Active
SHA256:8e91ca2d…
SHA256:1b74d5f3…
SHA256:f2c6a98e…
Rotated
Vaulted
Audited
3 keys rotated · 0 stale · audit logged
Discovery

Comprehensive SSH key discovery

Automatically find every SSH key across servers, user directories, and version control systems. Agentless scans that pull in keys the org has forgotten.

How it works
  • Agentless scanning of Linux and Windows hosts
  • Git repository scanning
  • Cloud instance discovery
  • Kubernetes secret detection
SSH key discovery inventory
Rotation

Automated rotation without downtime

Enforce rotation policies with coordinated updates to authorized_keys across every host. Rollback on failure keeps SSH access up while keys turn over.

How it works
  • Policy-based rotation schedules
  • Coordinated multi-host updates
  • Service continuity guaranteed
  • Full audit trail generation
SSH key rotation automation
Trust analysis

Trust relationship mapping

Visualize the graph of who can SSH where. Identify dangerous privilege-escalation paths, lateral movement risk, and detect key-based backdoors.

How it works
  • Interactive trust maps
  • Attack path visualization
  • Risk scoring per relationship
  • Remediation recommendations
SSH trust relationship graph
SSH CA

Short-lived certificates instead of static keys

Replace static SSH keys with an internal SSH Certificate Authority. Issue user and host certificates with configurable validity and principal constraints.

How it works
  • User and host certificates
  • Configurable validity periods
  • Principal constraints per cert
  • OpenSSH ecosystem compatibility
SSH certificate authority operations
Complete SSH governance

Every SSH key. Under management.

The complete toolkit for discovering, rotating, and auditing SSH access.

Access control
Manage who has SSH access to what with granular RBAC and temporary grants.
  • Role-based access control
  • Temporary access grants
  • Approval workflows
Orphaned key detection
Find and remove keys for departed employees and unused accounts.
  • Inactive key identification
  • Offboarding automation
  • Unused key cleanup
Security monitoring
Real-time alerts for weak algorithms, unauthorized keys, and usage anomalies.
  • Weak algorithm alerts
  • Unauthorized key warnings
  • Usage anomaly detection
Session recording
Record and audit SSH sessions for compliance and forensics.
  • Full session recording
  • Playback & search
  • Command logging
Compliance-ready audit
Complete SSH inventory and access controls for audit evidence.
  • Complete key inventory
  • Access change history
  • Evidence export
Policy enforcement
Block weak algorithms and mandate minimum key sizes at authorization time.
  • Algorithm allow-lists
  • Minimum key size rules
  • Fingerprint pinning

From SSH key programs in production

500K+
SSH keys managed
60%
Orphaned keys discovered on average
90%
Risk reduction
Case study
Fortune 100 · Financial services

Rotated 312k SSH keys and cut orphan keys by 71% in one quarter.

Our audit finding said "unmanaged SSH keys" three years running. TigerTrust found the graveyard, mapped every trust path, and rotated everything without a single outage.
Head of Infrastructure Security
312k
SSH keys rotated
71%
Reduction in orphaned keys
0
Access outages during rotation
Integrations

Works with every tool in your stack

Sync identity, orchestrate access, and record sessions with the tools your ops team already runs.

Okta
Identity
Azure AD
Identity
Google Workspace
Identity
HashiCorp Boundary
Access
Teleport
Access
HashiCorp Vault
Secrets
AWS Systems Manager
Cloud
Ansible
Config Mgmt
Kubernetes
K8s
GitHub
SCM
PagerDuty
Alerting
ServiceNow
ITSM
FAQ

Frequently asked questions

Agentless scanning uses your existing SSH access (a scan account or short-lived TigerTrust-issued cert) to enumerate authorized_keys, /etc/ssh/, user home directories, and common vendor paths on each host. For cloud fleets, we pull instance metadata and IAM-attached keys from AWS, Azure, and GCP. Git repository scanning catches keys accidentally committed to source. Optional lightweight agents cover Windows OpenSSH, containers, and hosts behind NAT. Every scan is read-only until you turn on remediation.
TigerTrust rotates keys with an add-then-remove pattern: install the new authorized_keys entry, verify SSH access with the new key, then remove the old entry. Multi-host rotations run in a coordinated wave so operators never lose access mid-flight. If the new key fails a verify step, rollback is automatic and the wave halts. Long-running sessions are unaffected because they use existing TCP connections, not authorization at each command.
For most estates, yes — and TigerTrust ships an SSH CA to make the migration realistic. User certificates (with configurable TTL, principals, and force-command) replace the pile of static keys sitting in authorized_keys. Host certificates replace known_hosts warnings with proper CA-signed host identity. You can migrate one host group at a time; static keys and certificates coexist through the transition. Post-migration, orphan-key risk drops toward zero because there's nothing to orphan.
Break-glass workflows issue a time-limited SSH certificate (typically 15-60 min) after multi-party approval, with the full session recorded. The certificate is bound to a specific incident ticket and set of principals. When time expires, access ends automatically — no cleanup required. Emergency access outside normal hours can be granted with a documented on-call justification that's reviewed in the next audit cycle.
Session recording is optional and configurable per user, per host group, or per certificate class. Recordings capture terminal I/O (or full pcap for high-security estates) with searchable command logs. Sensitive strings (passwords typed at prompts, private key material) are automatically redacted. Storage is encrypted at rest in your tenant. Retention windows are configurable per compliance regime; some customers keep 7 days for ops, others keep 7 years for regulated workloads.
SAML 2.0 and OIDC with any provider — Okta, Azure AD, Google Workspace, Ping, JumpCloud, Auth0, Keycloak — for user login to the TigerTrust console and for signing SSH user certificates. SCIM provisioning keeps user and group state in sync; offboarding an employee in your IdP automatically revokes their SSH access across every managed host in minutes.

Take control of SSH. Close the backdoor.