3 ms·
You aren't. It is the same with Yubikeys, if you use them. You are supposed to generate a certificate per user and device they are using for authentication, whi
by Metus 6y ago
You aren't. It is the same with Yubikeys, if you use them. You are supposed to generate a certificate per user and device they are using for authentication, which is not a big deal at least for remote login on servers, as you can set an arbitrary number of valid SSH keys.
- corty 6y agoYou are supposed, yes, but it is not necessary with Yubikeys. You can still import private keys into your Yubikey. At work we are using this for group access to some appliances that annoyingly limit the number of SSH authorized keys you can teach them.
- namibj 6y agoAlso, there are arguments against generating RSA keys with closed-source software (don't tell me that's all pure hardware in a smartcard). For one, generating keys that are vulnerable to something exotic is very much a viable threat, and yubikeys in particular had an issue where some accidentally created very weak keys. Sure, you need to make sure the key doesn't leak on it's way, but that's not really the issue.
- Xylakant 6y ago> and yubikeys in particular had an issue where some accidentally created very weak keys. So did Debian between 2006 and 2008 https://certlogik.com/debian-weak-key-check/ https://certlogik.com/debian-weak-key-check/
- corty 6y agoYes, but software is easier to fix and the problem is easier and more probable to find.
- namibj 6y agoMore importantly: you can check the key generator to not include a Dual_EC_DRBG.
- namibj 6y agoIn OpenSSL. Not in GnuPG. I'm not claiming the latter necessarily has better code, but the former's bad code quality is known.