3 ms·
Yes. Nobody asked me to do so, but all my setup (SSH auth, encryption, password manager, mail signatures) is build around GPG, so it was easy to add the signin
by StreakyCobra 8y ago
Yes.
Nobody asked me to do so, but all my setup (SSH auth, encryption, password manager, mail signatures) is build around GPG, so it was easy to add the signing in my git config.
I use a RSA8192 key as master key so it can last for a while. Then I have RSA4096 subkeys for signature, encryption and authentication. All subkeys are on my Yubikey configured with touch to operate. So when I am on a computer, I plug my Yubikey in there, and whenever I want to do a SSH login, a git commit signing, a password access (pass), a mail signing or anything else GPG related I have to touch my Yubikey.
The setup of such system is not so trivial, but once it is done it is working really well. My digital identity is build around my GPG keys, and they are stored safely in my Yubikey, and to operate them I have to be physically there and press it, so it can not be used remotely if my computer is compromised.
- pjc50 8y agoWho did you get to sign your keys? Are you using keybase or some other PKI/WOT system? (Same questions apply for everyone in this thread saying "yes")
- StreakyCobra 8y agoI have only one friend who signed it, my only friend nerdy enough to use GPG. For most of my usages (SSH, password manager, personal encryption) there is no need of a WOT. For the git commits signature, I have put my public key on Github so there is the "Verified" label aside my commits, but I don't think anybody has used this information yet. And for the email signatures, it is useless without a WOT, it is the reason why I do not bother to sign them anymore. As someone else said in this thread: «I just like that little bit of extra “yes, this was me” onion layer of security.»
- op00to 8y agoI have a literal stack of yubikeys after getting many of them shoved into my hand at trade shows. I'd love to actually use them for anything but OTP. Can you document this process? Care to share your setup? How do you handle, if at all, ssh/gpg on a mobile device? Is it possible to have both yubikey based cert authentication for SSH/GPG in addition to normal password based cert auth on the same server/user? Does this work on MacOS as well as Linux?
- thraxil 8y agoWhat you need to do is a bit platform-dependent, but Trammell's guide for MacOS is good: https://trmm.net/Yubikey https://trmm.net/Yubikey I run Linux but adapting his guide to what I use was the clearest path I found. Do note that only some of the Yubikeys support GPG. The cheaper ones (that you might be getting for free) are OTP only. Git signing is pretty straightforward once you have it set up for GPG. I have not attempted mobile at all.
- tempotemporary 8y agoHere’s a decent guide: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide PS I’d love to get some shoved into my hand. Paid $100 for my pair.