3 ms·
> 2FA for ssh Correct me if I'm wrong, but isn't this what password-protected private key encryption is?
by dev_dull 8y ago
> 2FA for ssh
Correct me if I'm wrong, but isn't this what password-protected private key encryption is?
- wiredfool 8y agoNo. Keys are easily (and persistently) added to ssh-agent, at which point it is easy to forward and will generally silently authorize without any further user interaction. That reduces it to a single factor. Compare that to a totp challenge or a yubi key plus a password. Having one of them won’t get you the other.
- mgbmtl 8y agoThe author probably meant "two-step" (out of band verification) rather than two-factor.
- imthenachoman 8y agoA pass phrase on a certificate is two step. Password + TOTP is two factor.
- LIV2 8y agoThe problem with that is that your users can always generate a key without a passphrase at all and you have no way of knowing
- ohithereyou 8y agoYou are incorrect. The only factor used there is the key. The password simply decrypts the key to perform the requested authentication. 2FA would be private key (password-protected) and a separate (most likely one time use) password. Something you have (key that you decrypted) and something you know (the one-time password).
- blamarvt 8y agoWhat I feel like all the responses missed is that while you're right in that a password-protected private key provides a second factor... what is typically meant by 2FA is two factors checked by the server. The server has no way to know you're using a password-protected key so it shouldn't really be regarded as a factor.
- rkeene2 8y agoIf the private key cannot be read by anyone and the user must authenticate to get the device to sign the authentication request, then it could be considered 2 factor by some interpretations.