Difference between CA and cert Ssh authentication themes Case A: unknown host Case B: host already in known_host but ip changed Case C: host already known (ip/fqdn in ~/.ssh/known_hosts) Case D: host has client’s pub key in authorized_keys Ssh + certificates Reason why ssh host cmd not using .bashrc/.login/.zshrc Passwordless connexion to a server Glossary WARNING: many things in this memo are wrong or very wrong.