21 ms·
I've been using Krypton[1-4] for 2FA PGP and ssh. It uses a phone as a security token, instead of using a Yubikey. (I'm not affiliated, or even a paying custom
by osteele 8y ago
I've been using Krypton[1-4] for 2FA PGP and ssh. It uses a phone as a security token, instead of using a Yubikey.
(I'm not affiliated, or even a paying customer. I just benefit from freeloading off their freemium model.)
This is not in any way to take away from how impressive the OP's work is, how nicely it's written up, or the merits of: understanding this yourself, running on a Yubikey instead of a phone, and running independently of someone else's distribution chain (unless you build the phone app and daemon yourself) and infrastructure. If you're in the subset whose response to OP includes “I wish I could do this with my phone, and that someone else would set this up for me so I didn't have to understand it”, [1] might be of interest; otherwise, not.
[1] https://krypt.co https://krypt.co
[2] https://github.com/kryptco https://github.com/kryptco
[3] https://news.ycombinator.com/item?id=14490766 https://news.ycombinator.com/item?id=14490766 – previous, mostly-skeptical, HN discussion
[4] https://news.ycombinator.com/item?id=16915819 https://news.ycombinator.com/item?id=16915819 – more recent discussion
- crankylinuxuser 8y agoAndOTP can also handle u2f keys like this on android. And from the fdroid store, requires as card permissions and open source to boot. Building on this, in Centos epel, there is a package "google-authenticator" which can generate 2fa for your account. It can also be turned on via a pam policy for all accounts. There's also LinOTP which has a web service and web administration. If you need something more than just 2fa (like 2fa+salt) then you want LinOTP. And being able to integrate it into API calls is also really handy for re-requesting security access.