11 ms·
Using a Yubikey for GPG and SSH
- acdha 9y agoIf the author sees it, `enable-ssh-supprt` in the SSH example is typoed.
- gehaxelt 9y agoHi, thanks, I've updated the post!
- drdaeman 9y agoOn a tangentially related note - I wonder, are there any OpenPGP Cards with EdDSA support with a "true" tamper-resistant HSM? Gnuk-based tokens (FST-01, Nitrokey Start) support Ed25519 keys, but while there is no obvious security holes (i.e. debugging is disabled etc), they're most likely not safe if left unattended in hands of an untrusted third party.
- wyager 9y agoPretty sure the Ledger Nano S meets your criteria, but I gave up using it as a PGP card after some seriously questionable issues like the fact that pinentry would always ask for my PIN on the host machine even though I had it set to only ask on the “card”. It’s just a big mess all around. Same thing with FIDO. It only seems to work in chrome even though Firefox theoretically has support.
- Shoothe 9y agoFirefox supports the FIDO U2F spec to the letter while Chrome requires legacy polyfill script that doesn't use the same exact API. So it's possible to support both but it's not as straightforward as it should be.
- xfer 9y agoNano S pinentry works fine for me; you need enable-pinpad-varlen option for scdaemon.
- 05 9y agoNothing is safe if left unattended. It’s trivial to make a ‘proxy’ RF device that sends your PIN to the attacker and receives whatever data you would expect from your original hardware token.
- jopsen 9y agoat the end of the day no encryption is perfect... security is all about making it harder for an attacker. A physical device certainly raises the bar.. that said the RF proxy attack is interesting, I'm sure it's non-trivial to do, as the device has to look legitimate. Nonetheless I better wrap my laptop in tinfoil from now on :)
- bascule 9y agoAs a Yubikey fanboi since 2013, who was very excited about the prospect of using it for airgapping GPG and SSH keys circa 2014, 2018 me says: "you almost certainly don't want to do this" Let's start with SSH. It's just plain unstable. If you try to set this up, you WILL have constant stability problems. I can assure you I have both personally experienced them and asked several other people who have attempted it to confirm that they too have various timeouts or other errors. One alternative is PIV. PIV is even more of a pain in the ass to get set up, and has similar stability problems. If I have a prescriptive recommendation for SSH, set up Duo for 2FA and use Yubikey-AES in "long press" mode (putting the key in slot 2). This gives you a strong hardware-backed authentication factor and protection against "Yubispam" (i.e. accidental credential leakage, a problem more severe than most would consider it) As for GPG, well... GPG is a tire fire. I also went through the Yubikey GPG PIN bypass (not their fault, but since Yubikeys cannot be field patched, this involved physically rotating every key, which Yubico replaced for free, but still). GPG suffers similar random faults, and gpg-agent can die in a fire, but at least unlike SSH you're probably not using it as frequently. Still, getting things set up is ridiculously arcane, thanks to gpg being a byzantine tool and the crazy mutable state nature of ~/.gnupg If you end up attempting to replicate this sort of setup, I can bet you dollars to donuts you will wind up asking yourself "Why did I think this would be a good idea?" after a few months
- viraptor 9y agoThat's very much not my experience. I agree that the setup is harder than necessary and if you get something wrong the errors are not helpful. But once it works, it works. I've been using yubikey with gpg-agent for ssh auth for years and it generally just works. I've not seen the stability problems you experienced.
- thomashabets2 9y agoThis is much more stable for SSH than the article: https://blog.habets.se/2016/01/Yubikey-4-for-SSH-with-physical-presence-proof.html https://blog.habets.se/2016/01/Yubikey-4-for-SSH-with-physic... (and also has physical presence proof). I've been using it for years on many machines. It's great. It's worked perfectly. Yes, the gpg-agent solution proposed in the article (which is what I used before PIV) was less stable. Nowhere near as bad as you describe though.
- thomashabets2 9y agoI prefer a physical presence proof for SSH instead of this proposed solution: https://blog.habets.se/2017/10/Yubikey-for-SSH-after-the-infineon-disaster.html https://blog.habets.se/2017/10/Yubikey-for-SSH-after-the-inf... (long version here: https://blog.habets.se/2016/01/Yubikey-4-for-SSH-with-physical-presence-proof.html https://blog.habets.se/2016/01/Yubikey-4-for-SSH-with-physic...) Before that I used the method described in the article, blogged at https://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO.html https://blog.habets.se/2013/02/GPG-and-SSH-with-Yubikey-NEO....
- Shoothe 9y agoThe blog post you linked to is using the PIV applet on Yubikey. You can do touch based OpenPGP operations on Yubikey too: https://developers.yubico.com/PGP/Card_edit.html#_yubikey_4_touch https://developers.yubico.com/PGP/Card_edit.html#_yubikey_4_...
- Xylakant 9y agoOnly for YK4, the old neos and YK3 don’t seem to support that. (Makes me consider buying a YK4 right now)
- nukeop 9y agoYubikey is very useful as a 2FA authenticator. I wouldn't use it for SSH and GPG. I wish there were more websites that supported U2F out of the box, or supported using Yubikey as an authenticator without first adding a mobile phone number, which I don't share on a principle.
- hollander 9y agoI have a Yubikey on my keychain, and never use it. I'm still looking for that application that will make me want to use it daily. I was thinking about using it to unlock my Mac, hoping this would add to its security after Meltdown and Spectre. Maybe add a second admin account which would require Yubikey. Then if that fails, I have another admin account without Yubikey as fallback login. My main problem is how to handle the loss of the key. Now I have one, but how do I handle the loss of one or more keys and can I lose access to my encrypted laptop? Same goes for Lastpass or other password managers where 2FA might be used. On the other hand, if I have an accident with head trauma and forget my passwords, what then?
- Shoothe 9y ago> Now I have one, but how do I handle the loss of one or more keys The same way you handle loss of keys to your home, car, etc. - you buy a second pair. If you're using OpenPGP you can provision them with keys any time so it's not a problem but if you're using U2F then you better add at least two to all your services (Yubico has a cheap U2F only key).
- ben1040 9y agoYep. I got multiple U2F keys. One is on my keychain, another is in a drawer in my desk, and a third is in a safety deposit box at the bank with my other important documents.
- serf 9y ago>My main problem is how to handle the loss of the key. if using for 2fa, most offer a way to turn 2fa off temporarily in case of a key-loss. I suggest buying more than one, associating them both with whatever task, and throwing one in a safe. It's less-than-ideal, but better than losing access completely when your keys are stolen or destroyed.
- kojiromike 9y agoUsing a sc like yubikey is great for security, but has performance implications for parallel tasks like salt-ssh across a bunch of hosts. Yubikey can only handle a single thing at a time, and is a touch slow, so if you are using salt-ssh to run a command on multiple servers, and if that salt-ssh happens to use GPG to decrypt pillars, then you're going to be waiting hundreds of times longer than you would using the vanilla, parallelizable ssh agent and scdaemon-free gpg-agent.
- pastage 9y agoI use GPG signed tar balls for that, mostly it's just to run scripts on multiple servers, but also useful for file transfers. You still have to fix secure transfers between hosts but you do not authenticate the connecting clients, but your client just need to verify host keys to protect against MITM. Works on pretty large installations. I started doing it like this when I only had Debian machines, and just used apt and Deb archives, but I never could find the time to hack Apt to be a perfect fit for it and it ended up being hell on other OS.
- lrvick 9y agoI feel the author missed a critical step. You want to enable user interaction flags to defend against someone with remote access to your machine. $ ykman openpgp touch aut fix $ ykman openpgp touch enc fix $ ykman openpgp touch sig fix This will require the yuibikey be physically touched for each sign/decrypt/ssh operation which while simple is something a remote attacker can't perform. For more detailed notes from me deploying commit signing and ssh via yubikey at three orgs see: https://github.com/lrvick/security-token-docs https://github.com/lrvick/security-token-docs * Edit: you want to use "fix" instead of "on" to prevent an attacker from just turning it off again.
- jlgaddis 9y agoInstead of using those backticks (which don't work here), indent each line by two spaces. It'll render like this: $ ykman openpgp touch aut fix $ ykman openpgp touch enc fix $ ykman openpgp touch sig fix Edited after parent's edit: s/on$/fix/g
- lrvick 9y agoFixed, thanks.
- lima 9y agoWarning: "fix" is permanent. (that's the whole point of it)
- atmoz 9y ago> you want to use "fix" instead of "on" to prevent an attacker from just turning it off again. An attacker also must know you admin PIN (required to change this setting), so there is really no need to use "fix" instead of "on". To be able to toggle this off, you must reset your yubikey (paraphrasing the docs).
- EngineerBetter 9y agoOne of our engineers wrote a series of blogs about how to use a Yubikey for SSH auth, OTP2FA, U2F, and logging into 1Password on shared machines. http://www.engineerbetter.com/blog/yubikey-all-the-things/ http://www.engineerbetter.com/blog/yubikey-all-the-things/ http://www.engineerbetter.com/blog/yubikey-ssh/ http://www.engineerbetter.com/blog/yubikey-ssh/ http://www.engineerbetter.com/blog/yubikey-static-secret/ http://www.engineerbetter.com/blog/yubikey-static-secret/ http://www.engineerbetter.com/blog/yubikey-2fa/ http://www.engineerbetter.com/blog/yubikey-2fa/ I wish AWS supported U2F, it'd make my day a lot less frustrating. We do a lot of pairing and rotating on shared machines, so it's really danged useful.
- lrvick 9y agoFor AWS you can use your yubikey indirectly for now via "Yubico Desktop" or "Yubico Authenticator" which emulate TOTP mode. You can then go through the "Virtual MFA" flow in AWS and keep the TOTP secret inside the yubikey with a touch requirement. This is nowhere near as ideal as U2F but it is a huge step above Google Authenticator which stores all secrets in plaintext in an sqlite database. Also the 2FA support of 1password is entirely cosmetic if an attacker has malware on your machine. It decrypts your entire database against one secret. I would encourage consideration of solutions that only decrypt the credential being reqested that don't expose the decryption key to the system: https://github.com/lrvick/security-token-docs/blob/master/Use_Cases/Password_Mangement.md https://github.com/lrvick/security-token-docs/blob/master/Us...
- stcredzero 9y agois a huge step above Google Authenticator which stores all secrets in plaintext in an sqlite database. ...I'm beginning to feel angry again! WTF Google? Why isn't Google Authenticator using an encrypted store with the keys stored in the iOS enclave?
- gruez 9y agoit's not. cursory search: https://dpron.com/recovering-google-authenticator-keys-from-ios-backups/ https://dpron.com/recovering-google-authenticator-keys-from-...
- Tharkun 9y agoI lose things. Frequently. Key fobs have fallen off my key chain. Someone once snail mailed me a flash drive which I'd lost (and which contained a single scanned invoice). I don't like physical access tokens. House keys are kind of a necessary evil (and I'm paranoid of losing them). But that's as far as I'm willing to go. Everything else can just live in my head. Including the strong passphrases to various SSH keys, GPG keys and whatnot. For anything I don't want to remember, I use pass.
- jlgaddis 9y agoI've, fortunately, never lost my keys -- including my Yubikeys -- but I keep spares just in case I ever do. When Yubico shipped me two new replacement Yubikeys (recent RNG issue), I just tossed them in the safe. I've also got a USB flash drive in there (in a tamper-evident bag) with a LUKS-encrypted filesystem that contains a backup of my GPG keys. I've got another such USB flash drive safely stored at another location too.
- jopsen 9y agoI leave my yubikey nano in my laptop at all times. Security is that: (A) usage requires touch; (B) if my laptop is stolen I'll notice :)
- insomniacity 9y agoAll of you guys using a Yubikey, seriously, in production - do you have another one prepped, tested and sitting in a safe? I just feel I have to look at the price, and order two, or it's just a toy.
- akerl_ 9y agoSortof. In practice, I have 2 "live" yubikeys per purpose, since I want a USB-A and USB-C set depending on whether my computer is plugged in to the hub on my desk or mobile. That gives me redundancy in case I accidentally dropped one in a blender or whatever. But also for anything high-criticality (basically anything where losing both yubikeys would lock me out permanently without further backups), I have another yubikey sitting physically-secured. It works out nice, since that's the same approach I was taking w/ "security question" answers and other recovery tokens.
- BostonEnginerd 9y agoYou can generate the keys on a Raspberry Pi or similar, transfer them to the Yubikey, and keep the backup in a safe place.
- alibert 9y agoMy Yubikey is provisioned with a SSH key generated on an air gaped laptop running Tails OS (live cd). The master key and subkeys were then saved on a separate encrypted SD card at the same time for backup.
- alanpost 9y agoWe use Yubikey for our production systems and yes: every operator has two keys that have been configured and registered in our access database. We decided though not to make our backup keys hot. It's a manual operation to enable it. The risk that everyone could simultaneously lose their key was lower than the risk of a backup key being lost and then used--since a person isn't likely to routinely check on their backup keys the later problem may go undetected for some time, whereas you know the day you lose your primary key and must report that situation anyway.
- r3bl 9y ago
- krrrh 9y agoAn alternative to this is https://krypt.co/ https://krypt.co/ which generates keys on your phone’s secure element/enclave and communicates with your laptop via bluetooth. It has a straightforward script to copy another public key from a backup phone to all your authorized servers, and the UI is excellent for signing git commits and authorizing ssh sessions. Doesn’t yet support U2F.
- 616c 9y agoWhen the secure enclave came up in the context of contactless payments at a 34CCC talk, it was suggested outside of Apple as an iPhone vendor, the type of card operation requiring it are avoided by Google and others because lack of cultural and technical buy in from HW devs. https://media.ccc.de/v/34c3-8965-decoding_contactless_card_payments https://media.ccc.de/v/34c3-8965-decoding_contactless_card_p... I won't buy into iPhones, HNers can flame away. Does this service get me anything as an Android user?
- thanatos_dem 9y agoNo real benefits that I’m aware of, and until Google starts to care about privacy more I wouldn’t expect them to invest in developing a secure coprocessor like the Secure Enclave, so you’ll probably be limited to 3rd party alternatives such as yubikey for the foreseeable future.
- lrvick 9y agoThe Android team has actually made a lot of progress on this front, and unlike solutions by Apple, Google lets their solution be audited by anyone as they release all the source code. Android has the hardware backed Keystore API for interacting with secure elements. Integration for this started in android 6.0 and is mandatory in 8.0. https://source.android.com/security/keystore https://source.android.com/security/keystore https://android-developers.googleblog.com/2017/09/keystore-key-attestation.html https://android-developers.googleblog.com/2017/09/keystore-k...
- 9y ago
- cjbprime 9y agoHuh, is using SSH on a GPG key safe? Can't the server trick you into signing a "challenge" that is actually a meaningful statement?
- jopsen 9y agoNo, 1) GPG has built-in support for this; presumably they are smart 2) GPG has an authenticate bit, which is required on the key in question. 3) You can (and typically will) create a separate sub-key, with the authentication bit set.
- akerl_ 9y agoThe "authenticate" bit isn't really material here. GPG keys are, at their heart, just asymmetric private keys (most typically RSA these days, but there are plenty of other options). The authenticate/sign/certify bits are flags that client tools use to know which key to pick, they aren't enforced anywhere. The reason your auth key is used for auth and signing key is used for signing is just because most GPG tools are helpful. It's also worth noting that an ssh agent using agent forwarding exposes use of all the keys it knows about, not just the one used for the initial connection. So if you SSH to 1.2.3.4 with "-A", that host has the ability to poke your agent and ask for any keys it's got loaded up. The "presumably they are smart" bit is also rather concerning. Being smart is generally not protection against mistakes. This isn't to say that gpg-agent allows malicious action, but we should start from a presumption that bugs exist, rather than just assume they don't.
- jlgaddis 9y ago> So if you SSH to 1.2.3.4 with "-A", that host has the ability to poke your agent and ask for any keys it's got loaded up. I'm sure you know this but just to be clear... if you're using "-A", that host has the ability to ask for operations to be performed using any keys it's got loaded up. It can't just say, "Lemme have all those private keys you got!". That's the primary purpose of storing them in a separate device -- the actual keys themselves become inaccessible and aren't exposed. Again, the device keeps the keys internally and performs operations using them on your behalf. Besides, in my case, even with an "offline master" key and three subkeys, the agent still only knows about the authentication key. The others don't get loaded into the SSH agent. I don't even use agent forwarding in the first place, but that's beside the point.
- sufficient 9y agoOn Android, we provide the OpenPGP implementation OpenKeychain that now also supports an impressive list of Security Tokens (https://github.com/open-keychain/open-keychain/wiki/Security-Tokens https://github.com/open-keychain/open-keychain/wiki/Security...). In our newest release, we also support YubiKey 4 over USB-C, which is a great alternative to NFC (which is only support by YubiKey NEO). Regarding SSH: We submitted a pull request to ConnectBot. You can try it out if you like: https://github.com/connectbot/connectbot/pull/567 https://github.com/connectbot/connectbot/pull/567
- fhenneke 9y agoI have recently added YubiKey/OpenPGP card support to the official ChromeOS SSH app Secure Shell. While key generation is not yet supported, using an already set up Yubikey for SSH authentication on a Chromebook should be entirely pain-free: https://chromium.googlesource.com/apps/libapps/+/HEAD/nassh/doc/hardware-keys.md https://chromium.googlesource.com/apps/libapps/+/HEAD/nassh/...
- alexk 9y agoAlso, check out how U2F works and how to use YubiKey with Teleport/OpenSSH: https://gravitational.com/blog/teleport-now-supports-u2f/ https://gravitational.com/blog/teleport-now-supports-u2f/
- Proven 9y agoThe trouble with this shit isn’t those commands that work, but those that don’t, and buggy packages in buggy distros.
- innagadadavida 9y agoThere is a module to make it work with touchbar MBPs fingerprint readers. Not sure if this is custom to our work or something that ubikey provides. It’s pretty seamless and much safer than using just a ubikey.
- forgotmypw 9y agoToo bad that USB extension cord is trojaned...
- jopsen 9y agoyou still can't copy the key :)
- Zombieball 9y agoI believe the following security advisory applies to anyone interested in starting to use GPG + Yubikey: https://www.yubico.com/support/security-advisories/ysa-2017-01/ https://www.yubico.com/support/security-advisories/ysa-2017-... Seems the recommendation is to ensure you generate GPG private keys off the YubiKey (if you have an affected device).
- danjoc 9y agoAll the keys affected are eligible for free replacement. Get a new one if yours is affected.
- Zombieball 9y agoYes I should’ve mentioned this. Thanks! Love my yubikey and would reccomend it to others.
- CraneWorm 9y agoI think Facebook uses Yubikey together with ssh for their (internal) 2FA https://www.youtube.com/watch?v=pY4FBGI7bHM https://www.youtube.com/watch?v=pY4FBGI7bHM
- Neutrion 9y agofor this kind of gadgets to truly win the favor of security-minded folk, first it has to be durable, which most of the product (include this one) failed to show.
- GunniH 9y agoI use the YubiKey for SSH auth on several servers but didn't go the GPG route. I opted for the challenge SSH mode using PAM. Using username "gunni". Using keyboard-interactive authentication. YubiKey for `gunni': Using keyboard-interactive authentication. Password: Last login: Tue Jan 14 14:07:02 2018 from X [gunni@box ~]# Works like a charm but I might look into the PGP variation if one of you can hard sell it to me.
- beezle 9y agoYubikey is a step in the right direction, but afaik it is still vulnerable at the pin entry level unlike a dedicated smartcard wtih pinpad reader. Likewise, gpg-agent, if I understand/remember it correctly, is also subject to attacks that would not be possible with the dedicated reader+card combo.
- urza 9y agoBtw you can also do SSH, GPG and 2FA also with Trezor, which has the advantage that for all functionallity you can have a one "24 words" seed backup, from which everything is determined. Oh and you can of course use it as bitcoin wallet :) SSH: https://doc.satoshilabs.com/trezor-apps/sshagent.html https://doc.satoshilabs.com/trezor-apps/sshagent.html GPG: https://github.com/romanz/trezor-agent https://github.com/romanz/trezor-agent 2FA: https://doc.satoshilabs.com/trezor-user/u2f.html https://doc.satoshilabs.com/trezor-user/u2f.html