macOS
brew install signmykeylocal Homebrew formula metadata
brew / rank 9923
Automated SSH Certificate Authority. Version 0.8.9 via Homebrew; verified 2026-09-13.
install
brew install signmykeylocal Homebrew formula metadata
overview
Automated SSH Certificate Authority
history
Signmykey is a client/server SSH certificate-authority tool that authenticates users and issues short-lived OpenSSH certificates.
Signmykey was created as an automated SSH certificate-authority service. Its documented architecture separates user authentication, principal lookup, and certificate signing, allowing local or HashiCorp Vault-backed signing.
The official documentation targets centrally managed SSH environments and integrates with Vault, LDAP, and OpenID Connect. The supplied package facts list Homebrew distribution, while the documentation also describes an Ubuntu package repository.
Administrators configure a Signmykey server with authentication, principal, and signer backends. Users point the client at that server and request a certificate, while SSH servers trust the configured CA and authorize certificate principals.
Signmykey packages an SSH-certificate workflow into a single client/server tool with pluggable identity, principal, and signer backends. It is notable for joining SSH access, enterprise identity, and short-lived certificate issuance without distributing long-lived authorized keys to every host.
security posture
broad file, network, media, or database tool signal.
blue risk · medium confidence · tool
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
/etc/signmykey/server.yml/etc/signmykey/client.yml~/.signmykey.ymlCredential-bearing paths to review before unattended agent runs.
/etc/signmykey/server.yml/etc/signmykey/server.keyexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
signmykey | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/signmykeyio/signmykey
install metadata
| Package key | brew:signmykey |
|---|---|
| Version | 0.8.9 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/signmykey |
| Homepage | https://signmykey.io/ |
| Repository | https://github.com/signmykeyio/signmykey |
| Upstream docs | https://signmykey.io/ |
| License | MIT |
| Source archive | https://github.com/signmykeyio/signmykey/archive/refs/tags/v0.8.9.tar.gz |
| Last updated | 2026-09-13T02:25:45Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | signmykey |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.