5 ms·
Was going to post this, less steps needed than op. I use my yubikeys as ssh keys and it's awesome, id suggest anyone who does should use the "cached" touch pol
by LIV2 8y ago
Was going to post this, less steps needed than op.
I use my yubikeys as ssh keys and it's awesome, id suggest anyone who does should use the "cached" touch policy as you can then connect to many servers within the 15 seconds without having to keep tapping (good for ansible runs!)
Mac users can just brew install opensc but you'll need to link/copy opensc-pkcs11.so into /usr/local/lib
On Windows you can use the pageant agent from https://risacher.org/putty-cac/ https://risacher.org/putty-cac/ and combine with weasel-pageant if you wish to use it as your ssh-agent in WSL https://github.com/vuori/weasel-pageant https://github.com/vuori/weasel-pageant
- gouggoug 8y agoDo you happen to have any tutorial handy that explain the steps needed for a mac os user to set that up? I have a U2F key from NXP that works very well as a 2nd factor auth for my email account, however, I'm having a really hard time finding documentation on how to use it to store my ssh private key. I just did `brew install opensc` and though it'd probably magiically work form there, but no luck.
- FineTralfazz 8y agoA U2F key isn’t enough, it needs to support smartcard PIV. The Yubikey does both, I’m not sure what other options there are.
- gouggoug 8y agoHa ok, thanks. I apparently am still confused about those!
- tialaramex 8y ago(Editing to point out that this is an elaboration, not a correction. ie here is why this doesn't work) The things a FIDO token / Security Key knows how to do are not really sufficient to authenticate with SSH public key Auth mode. Specifically FIDO tokens know how to magically create a new public key and a cookie and promise they can subsequently sign specific messages that prove they know the private key if given back the cookie. This is a very narrow feature set, deliberately to support the U2F / WebAuthn process only. Someone could add a completely new SSH Auth method that works with this but the existing SSH public key method requires that you start by claiming "Hey, I know this key, can that work?". Whereas a FIDO token may not (and yours doesn't) even be able to tell anyone which keys it "knows" (because in fact it doesn't really know them at all, they are effectively encrypted inside the cookies it relies on, but only it knows how to decrypt those!).
- gouggoug 8y agoThanks, that was useful
- akerl_ 8y agoAs a heads up, you shouldn't need to copy the opensc-pkcs11 library, you can instead launch ssh-agent with the -P flag to whitelist the library path. I have the following as an alias: yy () { opensc_path="$(readlink -f $(brew --prefix opensc))/lib/opensc-pkcs11.so" eval $(ssh-agent -P $opensc_path) ssh-add -s $opensc_path }