8 ms·
Show HN: Yubikey-agent – an easy to use Go ssh-agent for YubiKeys
- m3nu 6y agoI use it with PKCS#11 mode and can't confirm some of the drawbacks the author mentions under Alternatives: > The UX of this solution is poor: [...] and needs manual reloading every time the YubiKey is unplugged or the machine goes to sleep. I never have to re-enter the PIN after sleep and can even unplug it for a while to use the port for HDMI output. Still good to see some work in this space. Native OpenSSH support would be best of course.
- Boulth 6y agoYeah I had the same experience using OpenPGP applet on the Yubikey both on Linux and Windows. It just works. Maybe it was a problem once but got improved with time?
- DCKing 6y agoI can confirm the author's experience with Apple's SSH-agent implementation. It does not allow you to load Yubikey agent libraries from Homebrew's default /usr/local, which makes it an inconvenience to set up.
- FiloSottile 6y agoIt surely depends on the OS, and on the PKCS#11 implementation. I tested ykcs11 and OpenSC on macOS and they were like I described. I had started this project as a simple setup tool for PKCS#11 configurations and had to build the agent to get the UX I wanted. Also, not having to re-enter the PIN after unplug means it's being cached in memory rather than on device, which I'm not a fan of. In yubikey-agent that's handled by using a graphical pinentry during operation to avoid the manual unlock step.
- jopsen 6y agoHmm, gpg-agent has worked nicely for me. The biggest pain is that I have to reconfigure when I switch yubikey. (Yes, I have multiple keys with the same gpg key on each)
- noodlesUK 6y agoDoesn’t having the same key on multiple devices kinda ruin some of the point of the yubikey? What if you wanted to revoke one after you lost it? Also, how do you store your gpg key? I have a couple yubikeys, but I have different keys on each of them, and I find that works just fine.
- Boulth 6y agoIt's not a big problem because tokens lock themselves after 3 tries so even if someone got your token they'd have to guess it. Having separate subkeys for each token is nice but works best only with the signature subkey. For encryption it doesn't work as GnuPG encrypts only to one subkey. The same with authentication subkey: it doesn't matter if you revoke it because SSH doesn't understand OpenPGP revocations.
- jopsen 6y agoKeep it simple.. once the key is on an yubikey it's not going anywhere.. The biggest risk is that I loose the key.
- Boulth 6y ago> The biggest pain is that I have to reconfigure when I switch yubikey. This is planned to be fixed in GnuPG 2.3.
- jopsen 6y agoWow, how? Currently I understand that gpg records a card identifier. And my card doesn't have the same id. I suppose it'll be a long time before this hits stable distros anyways. But nice to see improvements :)
- Boulth 6y agoIt was some time when I read the explanation on how do they want to approach this but I guess the card identifier will no longer be needed (or all card ids will be stored). If you want to check it yourself https://dev.gnupg.org/T4695 https://dev.gnupg.org/T4695
- fidelramos 6y agoI want to mention a Yubikey alternative that runs on open-source firmware and software: OnlyKey [1] It has an onlykey-agent that works as an SSH agent [2]. It doesn't work as a GPG agent yet though, they are reportedly working on it. [1] https://onlykey.io/ https://onlykey.io/ [2] https://docs.crp.to/onlykey-agent.html https://docs.crp.to/onlykey-agent.html
- danieldk 6y agoYou may want to read the recent discussion on HN about OnlyKey before using one: https://news.ycombinator.com/item?id=21884184 https://news.ycombinator.com/item?id=21884184
- fidelramos 6y agoThank you very much for the link, I missed that discussion. I had no idea the security of OnlyKey was so terrible, in light of this I will stop recommending it.
- StavrosK 6y agoI'm really excited about the next SoloKey coming out soon.
- fidelramos 6y agoThank you for the alternative. Sadly it doesn't support SSH or GPG keys, does it? That was one of the selling points of the OnlyKey for me (and it being open source of course).
- StavrosK 6y agoI'm not sure if they will support those yet. I could never get SSH working well, whereas SSH with U2F works perfectly (and they do support that). I'm guessing they will add GPG key integration, as once the key can perform crypto operations, it's just a matter of host software.
- abricot 6y agoIs it considered good practice to create the key on the yubi and not have a backup? Or alternatively a master key to sign the key on the yubi so you can create a new subkey if you lose the yubi?
- m3nu 6y agoYou have 2 physical Yubikeys and no backup anywhere else. One way to achieve it is by generating it on a RAM disk and throwing it away, once it's on both Yubikeys. I blogged about it here https://blog.snapdragon.cc/2019/04/27/using-a-yubikey-to-secure-ssh-on-macos/ https://blog.snapdragon.cc/2019/04/27/using-a-yubikey-to-sec... (for macOS)
- sebazzz 6y agoWindows users might find this useful: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide
- brippalcharrid 6y agoIdeally each key will be generated on the device and be unexportable. That's a major part of the value of a Yubikey/smartcard/HSM, because it provides Non-Repudiation, and it enables you to be reasonably certain that it is impossible for the key to exist outside of the physical device. You can use multiple devices to generate multiple keys to give you persistent access in case a device fails or is lost. Software generally accommodates multiple (public) keys per client for this reason. With an SSH CA, the server ultimately trusts the CA key, and client keys are used for authentication via the client certificates. I think you can use Yubikeys and relatively inexpensive HSMs (eg. Nitrokeys) for this. https://framkant.org/2016/10/use-a-smart-card-or-hsm-to-securely-store-your-ssh-ca-keys/ https://framkant.org/2016/10/use-a-smart-card-or-hsm-to-secu...
- stavros 6y agoI have been trying to use Yubikey for SSH over the years, and everything has been a huge hassle that just didn't work well enough. Everything, that is, until SSH 8.2 came out. Using a Yubikey (or any other U2F-compatible key, which is a lot of them) is a breeze: Run `ssh-keygen -t ecdsa-sk -f ~/.ssh/id_ecdsa_sk` to generate a key from your Yubikey and you're done. You can even use Resident Keys mode (if your key supports it) to avoid having to carry the private-key-half around with you, you can load it straight from the Yubikey with `ssh-add -k`. This is the only way that lets you walk up to a machine, plug your key in and SSH to your server securely with just two commands. The downside is that both sides have to be running SSH 8.2+.
- brazzy 6y agoCan you register multiple devices for the same SSH key, so you have a backup in case one gets lost or breaks?
- StavrosK 6y agoNo, but why do you need to? Just add multiple keys to all hosts.
- brazzy 6y agoOh right, that's effectively the same thing...
- justincormack 6y agoWhy not just add the keys from each device to your machines? Doing secure key transfer between hardware tokens is way more complicated.
- danieldk 6y agoI use gpg-agent, but I agree it is often a pain. I will probably switch to U2F + SSH once more servers have OpenSSH 8.2. Do you know if this already works with GitHub?
- bonzini 6y agoWould it be possible (or would patches be accepted) to talk to the GnuPG scdaemon instead? This would let me use gpg-agent to sign and encrypt.
- exabrial 6y agoOk so this is neat; while the newest openssh client/server directly supports u2f keys, this is a badass shim that creates NIST-p256 compatible keys that are backed by a YubiKey.... man I wish this was a thing about 2-3 years ago! Personally I've been using gpg-agent for a 2 years now without issues. It's also nice because your ssh key could be signed and be discoverable on public keyservers (like keybase), but I don't see any cloud providers having that integration yet.
- xaduha 6y ago> The UX of this solution is poor Not surprising if you ask me, have you installed an applet for it? Do latest Yubikey even allow installing applets? Why are you using PIV for this? I was using https://github.com/philipWendland/IsoApplet https://github.com/philipWendland/IsoApplet with OpenSC and smartcards since 2016, no issues.
- urza 6y agoYou can also use Trezor.io instead of Yubikey for ssh login. https://blog.trezor.io/openssh-with-fido2-and-trezor-e565c2277 https://blog.trezor.io/openssh-with-fido2-and-trezor-e565c22... Advantage of Trezor is that it has better backup system and can be used for more things in general.