SSH KEY MANAGEMENT

SpanKey SSH Access Server

SpanKey is a core service running within WebADM, RCDevs’ core framework, providing centralized and secure key management

orange ORACLE ENGIE verizon
Illustration SpanKey
BNP Paribas Orange Oracle Engie Verizon
Product

Centralized Access Control

Granular identity-based access governance across your Linux infrastructure

Shared Accounts with Accountability

Convert a directory user into a shared SSH account by linking it to an LDAP group, members access it with their own SSH keys

Server Tagging (Fine-Grained Access)

Tag servers and allow access only to users or groups with matching allowed tags, simple segmentation for environments and teams

Master Keys

Shared accounts and privileged users (master keys) centrally managed for controlled privileged access

Recovery Keys

Recovery keys for secure emergency access, centrally managed

SSH Key Lifecycle Management

Full lifecycle control of SSH keys, from issuance to expiration and revocation

Automated Public Key Expiration

Define SSH key lifetime and enforce automatic expiration to reduce long-lived access and support policy-driven governance

Easy Keys Enrollment with
Self-Services

Users can register SSH keys through WebADM and self-service interfaces, with centralized policy control and immediate revocation when needed

Centralized SSH Key Revocation

Instantly revoke SSH keys across all managed systems from a single SpanKey administration point

SUDO & Audit Integration

Centralized SUDO control and complete audit visibility across all systems

Centralized SUDO

Centralized SUDO definitions per group, user and client system

Audit Integration

Auditd rules can be centrally managed and forwarded to the SpanKey server or a SIEM

Session Recording & Replay

SSH sessions can be graphically recorded and replayed through the WebADM Administrator portal

Infrastructure
Solution

Centralized SSH Key Lifecycle Management for OpenSSH

SpanKey integrates directly with OpenSSH using a lightweight agent that retrieves authorized keys at authentication time. Access decisions are evaluated against directory attributes and server context, without modifying standard SSH workflows

  • Native OpenSSH integration (no protocol changes)
  • Works with existing Linux and FreeBSD deployments
  • Directory attribute–based access evaluation
  • No local key distribution or synchronization mechanisms required
  • Designed for clustered WebADM environments

Multi-Factor Authentication for SSH Access

After SSH key validation, enforce additional user verification using password, OTP, or U2F. SSH private keys can also be securely stored on smartcards to strengthen credential protection and reduce the risk of key compromise.

Discover OpenOTP
Deployment

Where to use SpanKey

SpanKey runs on your WebADM Cluster and connects to Active Directory (or any LDAP directory). The Linux agent is available as RPM and DEB packages

Supported platforms

  • Oracle / RedHat / CentOS servers
  • Debian / Ubuntu
  • SUSE Linux
  • Raspberry Pi / ARM

Public key algorithms

Industry-standard public key authentication with OpenSSH:

  • RSA (1024, 2048, 4096 bits)
  • ECC (256, 384, 521 bits)
  • DSA (1024 bits only)
Trust

They Trust us Around the World

Global businesses trust RCDevs for secure identity and access solutions

+900
Clients

Trusted by over 900 clients globally, We provide advanced security solutions tailored to businesses of all sizes

1m
Happy Users

Over 1 million users trust RCDevs for secure authentication solutions supported by expert assistance

+60
Countries

RCDevs' security solutions are trusted in 60+ countries, delivering advanced authentication and identity management worldwide

+18
Years of Expertise

With 18 years of expertise, RCDevs delivers reliable and innovative security solutions built on deep industry knowledge

Blog

RCDevs Security Articles

Insights, product updates, and security best practices

We're here to help!

Reach Out to Discover SpanKey’s Full Capabilities

Contact us today and discover how SpanKey simplifies
and secures SSH key management