Ephemera

A Zero-Trust SSH Certificate Authority

Ephemera is a sovereign, air-gapped SSH Certificate Authority designed to replace static keys with short-lived, identity-bound certificates. No long-lived private keys on user devices. Certificates are issued just-in-time and expire automatically.

User WebAuthn Short-lived cert SSH Logged sudo

Properties

YubiKey / WebAuthn Setup

Ephemera uses WebAuthn-compatible hardware keys (such as YubiKey) to enforce physical presence for SSH certificate issuance and sudo approval. Learn more in our WebAuthn Guide.

  1. Run ephemera login
  2. When prompted, insert and touch your YubiKey
  3. The credential is registered and bound to your account
  4. Future SSH renewals and sudo approvals require physical presence

Documentation

Ephemera is open source under the Apache 2.0 license.
codeberg.org/Qarait1/ephemera