Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. SSH
  3. HIBA

HIBA

BSD-3-ClauseC

A flexible authorization layer for OpenSSH certificate-based authentication using host identities and grants.

Visit WebsiteGitHubGitHub
390 stars18 forks0 contributors

What is HIBA?

HIBA is an authorization system built on top of OpenSSH certificate-based authentication. It enables flexible, policy-driven access control by attaching host identities and user grants as extensions to SSH certificates, allowing target hosts to dynamically authorize users without manual configuration updates. It solves the problem of managing SSH access across large, dynamic host pools with minimal operational overhead.

Target Audience

System administrators, DevOps engineers, and security teams managing SSH access in environments with many hosts, especially those requiring granular, auditable access controls without relying on centralized authorization services.

Value Proposition

Developers choose HIBA because it extends OpenSSH's native certificate authentication with fine-grained, declarative authorization policies, eliminating the need to push authorized_keys files. Its local evaluation makes it robust for low-dependency or last-resort access scenarios.

Overview

HIBA is a system built on top of regular OpenSSH certificate-based authentication that allows to manage flexible authorization of principals on pools of target hosts without the need to push customized authorized_users files periodically.

Use Cases

Best For

  • Managing SSH access in large-scale, dynamic infrastructure (e.g., cloud or container fleets)
  • Enforcing role-based or attribute-based access control for SSH without centralized servers
  • Implementing last-resort or emergency access systems with minimal external dependencies
  • Auditing and compliance for SSH access through certificate-bound policies
  • Simplifying SSH key distribution and revocation in multi-team environments
  • Building custom certificate authorities with extended authorization capabilities

Not Ideal For

  • Teams not yet using OpenSSH certificate-based authentication for SSH access
  • Organizations requiring instant, centralized revocation of individual user grants without certificate expiration
  • Small-scale environments with static SSH policies where manual authorized_keys management suffices

Pros & Cons

Pros

Dynamic Policy Enforcement

Uses OpenSSH's AuthorizedPrincipalsCommand to invoke hiba-chk at connection time, enabling real-time authorization without pushing authorized_keys files, as described in the README.

Fine-Grained Access Control

Allows defining host identities (e.g., domain, owner) and user grants with constraints, enabling precise matching for authorization decisions based on host properties.

Low Infrastructure Dependency

Authorization is performed locally on target hosts via hiba-chk, making it suitable for last-resort or isolated SSH access without external services, as highlighted in the key features.

Flexible Metadata Support

Host identities and grants support custom fields beyond the mandatory 'domain', allowing adaptable policy definitions to match diverse infrastructure needs.

Cons

Complex Setup Requirements

Requires OpenSSH certificate-based authentication and specific versions (6.9+ for AuthorizedPrincipalsCommand, 7.4+ for tokens), adding significant initial configuration overhead, as noted in the prerequisites.

Limited Grant Revocation

Individual grant revocation is not yet implemented; the README admits relying on short-lived certificates or full certificate revocation, which may not meet all operational needs.

Non-Thread-Safe Library

The HIBA library is explicitly not thread safe, requiring callers to manage locking, complicating integration into multi-threaded certificate authorities, as warned in the developers section.

Frequently Asked Questions

Quick Stats

Stars390
Forks18
Contributors0
Open Issues2
Last commit1 year ago
CreatedSince 2021

Tags

#devops#openssh#authorization#security#system-administration#access-control#identity-management#ssh-authentication#ssh

Built With

l
libssh
O
OpenSSH
C
C++

Links & Resources

Website

Included in

SSH2.8k
Auto-fetched 20 hours ago

Related Projects

krkr

DEPRECATED A dev tool for SSH auth + Git commit/tag signing using a key stored in Krypton.

Stars1,571
Forks108
Last commit2 years ago
totp-ssh-fluxertotp-ssh-fluxer

Take security by obscurity to the next level (this is a bad idea, don't really use this please)

Stars946
Forks43
Last commit4 years ago
authy-sshauthy-ssh

Easy two-factor authentication for ssh servers

Stars793
Forks67
Last commit8 years ago
github-authgithub-auth

SSH key management for GitHub users

Stars390
Forks17
Last commit8 years ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub