The Keystore Server is a dedicated Ubuntu server responsible for the centralized storage and management of SSH and WireGuard public keys used throughout the infrastructure.
The purpose of the server is to provide a single source of truth for all approved public keys while ensuring that private keys are never stored on the system. Administrators can use the Keystore Toolkit to securely add, retrieve, and remove keys as infrastructure changes occur.
The Keystore Server provides:
| Item | Value |
|---|---|
| Server Role | Key Repository Server |
| VPN Network | 10.46.0.0/24 |
| VPN Interface | wg0 |
| VPN Address | 10.46.0.10 |
| Operating System | Ubuntu Server |
| Access Method | WireGuard VPN + SSH |
The following users are designated keystore administrators.
| User | Role |
|---|---|
| mbagen | Administrator |
| molossoumare | Administrator |
Administrators are members of the:
keystore-admin
group.
Only members of this group are authorized to:
The Keystore Server utilizes multiple layers of security.
Administrative access occurs through the WireGuard VPN network.
VPN Address:
10.46.0.10
Administrators authenticate using SSH public key authentication.
Password-based SSH login should be disabled whenever possible.
Each administrator uses an individual Linux account.
Shared administrator accounts are not permitted.
Access to the keystore is restricted using the:
keystore-admin
group.
Only members of this group may manage stored keys.
The keystore storage directory is protected through Linux ownership and permissions.
Ownership:
root:keystore-admin
Directory Permissions:
770
File Permissions:
660
The keystore stores:
The keystore does not store:
All toolkit actions are logged.
Examples:
/opt/keystore/
├── ssh.keys
├── wireguard.keys
└── logs/
└── keystore.log
Stored in:
/opt/keystore/ssh.keys
Format:
owner:ssh:public_key
Example:
mbagen:ssh:ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA...
Stored in:
/opt/keystore/wireguard.keys
Format:
owner:wireguard:public_key
Example:
mbagen:wireguard:f8muPw3rB163dDk0XuZLzSLuuyjJPOaTdkRVqer5lww=
The Keystore Toolkit provides a controlled interface for managing SSH and WireGuard public keys stored on the Keystore Server.
A system-wide alias is configured under:
/etc/profile.d/keystore.sh
This allows authorized administrators to launch the toolkit from any directory on the server.
To start the toolkit:
keystore
Only users with membership in the keystore-admin group are authorized to use the toolkit.
1) Retrieve Key
2) Add Key
3) Remove Key
0) Exit
Administrators can retrieve stored public keys.
Supported key types:
The toolkit displays all stored owners before prompting for selection.
Workflow:
Retrieve Key
↓
Select Key Type
↓
Display Available Owners
↓
Select Owner
↓
Display Public Key
Administrators can add new public keys.
Supported key types:
The administrator provides:
Format:
owner:type:public_key
Examples:
mbagen:ssh:ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA...
molossoumare:wireguard:f8muPw3rB163dDk0XuZLzSLuuyjJPOaTdkRVqer5lww=
Duplicate entries can be replaced when necessary.
Administrators can remove stored public keys.
Supported key types:
The toolkit:
Audit log location:
/opt/keystore/logs/keystore.log
Example:
[2026-05-06 14:32:10] USER=molossoumare - SUCCESS: wireguard key added for owner: mbagen
Logged activities include:
Document Name: Keystore Server Documentation
Server Role: Key Repository Server
Version: 1.1