Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

SSH Key Storage and Security

Michael Russo February 28, 2024

Hi All,

I'm a Bitbucket Administrator, and I have a question about storage of SSH keys.

Location 1: https://bitbucket.org/[organizationname]/workspace/settings/ssh-keys

Location 2: https://bitbucket.org/account/settings/ssh-keys/

 

Any Admin is able to register new SSH public keys in Location 1, and a user with the corresponding private key is then able to push code to Bitbucket without password prompts - no problem there.

Any User is able to register a new SSH key into Location 2, however Admins are unable to see those keys.

 

My questions are:

1. Are key creation/removal on the User (Location 2) level auditable events?

2. Is there a way to generate a report that shows all keys across both locations?

 

1 answer

1 vote
Ben
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 29, 2024

G'day Michael!

Welcome to the Bitbucket Cloud community!

User-level SSH keys are present in audit logging at the user level (and are only visible to that user) and cannot be queried at the workspace level - more information regarding the events found in the audit log can be found below:

As for reporting, this is not yet possible within the Bitbucket Cloud product but there is a feature request logged with our developers. Please feel free to Watch this feature request to receive future updates related to it and Vote for it to improve its visibility with regard to customer demand:

Cheers!

- Ben (Bitbucket Cloud Support)

 

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events