3 ms·
I did not knew about that, thank you! I instantly changed my SSH key for the generated key in my YubiKey Neo and use it everywhere. Here is a tutorial is anyon
by Walkman 8y ago
I did not knew about that, thank you! I instantly changed my SSH key for the generated key in my YubiKey Neo and use it everywhere.
Here is a tutorial is anyone is interested: https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PKCS11.html https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PK...
- bonyt 8y agoYeah, it's cool! A couple extra tips: - You can put "PKCS11Provider /usr/lib...." in your .ssh/config file (even tied to a specific Host block) to make it load the module automatically instead of having to use an argument every time you run ssh/sftp/scp/etc. - For windows, putty-cac works well with the built-in smartcard/crypto API (CAPI), even on machines where you don't have administrative access (like my work machine). It even has its own version of pageant, so it'll work with tools like WinSCP as well. https://risacher.org/putty-cac/ https://risacher.org/putty-cac/ https://github.com/NoMoreFood/putty-cac/releases https://github.com/NoMoreFood/putty-cac/releases
- Boulth 8y agoYep, putty cac works very nice. The only downside I found compared to gpg agent is that cac does not forget PIN when the card is removed (gpg agent does that and I like it).
- Walkman 8y agoI tried on both OS X and Linux, works fine, though on Linux it asks for the PIN every time, which is very annoying. Do you know a solution for that?