4 ms·
Public key authentication of clients (as opposed to servers), has been part of SSL since v1.0. This is just adding a misdirection, the underlying protocol is th
by rdancer 11y ago
Public key authentication of clients (as opposed to servers), has been part of SSL since v1.0. This is just adding a misdirection, the underlying protocol is the same X.509 we've had since the late 1980s.
The main problems are:
1. Certificate authenticity -- the key has to be added to authorized_keys on the server. This includes certificate revocation and expiration, and re-establishing trust after certificate is lost.
2. Private key management -- how do I migrate keys to a new browser or a new machine? Where are the keys stored anyways? Absolute PITA in every existing implementation.
3. Key generation -- we need some more user-friendly tools if this is to catch up
- jamiesonbecker 11y agoWe're working on solving a few of these SSH issues at Userify[1] (SSH key management) but I think you're right. Something like this could be even harder to spur adoption than SSL client certs, which browsers already support. (Here's an article[2] from 1998... almost two decades ago!) 1. https://userify.com https://userify.com 2. http://www.ibm.com/developerworks/lotus/library/ls-SSL_client_authentication/ http://www.ibm.com/developerworks/lotus/library/ls-SSL_clien...
- chrissnell 11y agoThe U.S. Military does a passable job of this with the Common Access Card (CAC). You insert it into a smart card reader and then visit the restricted-access website. Your browser/OS prompts you for a PIN which, I believe, is used to decrypt your private key. Your browser validates the remote site against a set of DoD-provided root certificates that you configure on your computer before hand. Then, some kind of key exchange happens--this has always been a bit fuzzy to me--and the keys on your CAC card are used to authenticate you to the remote site. It's not perfect, of course. You can lose your CAC card and then you're screwed unless you have a way to get new one. It requires a smart card reader which is not standard on most computers. The cards themselves can get damaged by corrosive liquids or sweat (learned this the hard way). Still, it's not a bad way of authenticating and I feel much better about it than a SSH private key that hasn't been encrypted with a passphrase.
- rdancer 11y agoFor example in Estonia, every citizen has an ID card, and every ID card is an ISO-7816 smartcard. So they can have this nationwide. Then again, that's a country of 1.3M, and you only get the card when you're 15yo. Foreign visitors obviously don't have one. These examples illustrate rather the near impossibility to implement this kind of a scheme successfully, even when backed by a state.