# Note that the matching is done with re.match()
'.*\.cert\.sunet\.se$':
sunet::server:
ssh_allow_from_anywhere: false