Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

202
Vistas
How to manage EC2 key pairs for multiple users?

I'm working in a team with 8 people. I need to create an EC2 intance. Just before I create the instance, EC2 lets me create a key-pair and then download it.

The problem is: That way I need to share the same private key for all 8 team members.

Now, what happens if tomorrow one of the teammates leave? I will need to recreate the machine with a new key pair.

How can I manage the keys correctly so every team member will have his/her unique key that is associate with his/her IAM user, so once he/she leaves the company, I will be able to invalidate his/her key?

over 4 years ago · Santiago Trujillo
3 Respuestas
Responde la pregunta

0

Try to avoid giving the PEMs for the instances to everyone, keep these with the Administrators in a tool such as a password vault.

Remember that to rotate these PEMs you would need to manually replace the authorized_keys on any Linux instance, and for Windows instances where you use this PEM to get the Windows password you would need to replace and launch with the new PEM.

AWS has a couple of solutions that help make secure access to your Linux instances easier:

  • If you do not require to actually SSH to the host, but just need terminal access you can make use of Session Manager. Using this tool you can access a terminal within the AWS console or connect via the CLI. Interactions with the terminal can be scoped to allow only specific commands with functionality for auditing built in.
  • If you would like to connect to a terminal, you can use EC2 instance connect. Using this option you can generate a temporary key and then provide this via the CLI to allow temporary access using this PEM. Once this command is run (and is successful) you will be able to connect to the instance temporarily using the SSH terminal with your temporary PEM.
over 4 years ago · Santiago Trujillo Denunciar

0

I suggest looking into using EC2 Instance Connect which uses temporary SSH keys and allows you to grant access using IAM policies.

Otherwise, I suggest using a tool like Ansible to manage the SSH keys on your fleet of instances so you can easily add or remove keys.

over 4 years ago · Santiago Trujillo Denunciar

0

Your question is not about Ec2 per se, but about the access control model you want to implement.

If all those 8 people need to have identified and individual access to the instance, the simplest way is to create 8 different users at the instance. Each one with a different ssh-key.

It can be done logging into the instance, using the key created for the ec2-user or ubuntu user, then creating each of the users and distributing.

If all you need is one different key for everyone to login into the same user, just ask people to create ssh-keys and share the public key with you. Then you put all of them into the default user .ssh folder.

When someone goes out, simply delete the ssh-key. You can even keep their user for historical reasons.

If the number of instances go up, you should invest into a centralized login management tool like LDAP

over 4 years ago · Santiago Trujillo Denunciar
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda