13 ms·
How to use FIDO2 USB keys with SSH
- RL_Quine 6y agoBe aware literally nothing supports this unless it's your own kernel. Gitlab? No. Github? No. My gateway with a hand built gentoo kernel? Yes. It seems functional, but you've also got to be aware that `ed25519-sk` and `ecdsa-sk` have sort of spotty support in the devices too. `ed25519-sk` does not work on a Yubikey <5, for example.
- StavrosK 6y ago> Be aware literally nothing supports this unless it's your own kernel. Ubuntu 20.04 and later supports this, and, since that's LTS, it means that quite a few servers and machines will be supporting it already. Github/Gitlab aren't supporting it yet, but given how great it is for security, I think they have a big incentive to speed up support. > ed25519-ek does not work on a Yubikey <5, for example. That's no problem, since you can just generate an ECDSA key instead, but yes, not all keys have hardware support for all algorithms.
- deleted 6y ago[deleted]
- Freak_NL 6y agoDebian 11 too, out of the box. It took a bit of work to use a newer openssh-client on my Ubuntu 18.04 laptop, but that was manageable.
- nobodyshere 6y agoNot exactly true. Ubuntu 20.04 supports this out of the box and lots of VMs therefore also do.
- knorker 6y agoNot only that, but there's billions of devices out there that don't support it. I can SSH to my AP, my home router, all routers at basically any ISP. None of those support this. Most of them probably never will, until they're thrown away and new ones bought in 5-10 years. Bottom line: This can't be your only key. So why bother? Why not use PIV mode/smartcard/other, which does work with every single one of these billions of devices, because they have no server-side requirements like these.
- ptspts 6y agoHere is another tradeoff. Many PIV smartcards (such as YubiKey 4, if I'm not mistaken) are able to store only a single private key. With U2F (ecdsa-sk), the number of SSH keys is unlimited. Another tradeoff. Some users may be using a cheap or old token (without PIV support) or a token with a private key slot already used for something else. Now, with a software-only upgrade (on both SSH client and server), they can user their existing token for SSH authentication.
- knorker 6y agoAh yes, that's a good point. It is not great that you leak your identity by using pubkey (ssh whoami.filippo.io).
- michaelt 6y ago> be extra careful when using SSH forwarding (the -A option), as the server can then ask your computer to authenticate to other servers on your behalf. That would require an extra press of the token's button for each extra authentication, right?
- StavrosK 6y agoThat's a good point, I haven't tried it but I think you're right, which is another great benefit of using hardware tokens.
- staticassertion 6y agoI would assume the agent caches the key for signing. Would someone please confirm this? If it did require another key press that would be pretty huge.
- tialaramex 6y ago> I would assume the agent caches the key for signing. For that to happen the agent would need to have some way to get the key out of the FIDO authenticator, which is deliberately not intended to be possible. I will now go away and confirm that this behaves as I expected and update this message shortly. Update: Yes, the OpenSSH agent just has code to go talk to the authenticator each time it needs to sign something. The authenticator may or may not (most seem to not) allow this to happen without verifying user presence (e.g. via a button press or touching a contact) but even if your device does allow this the signed payload says whether the user was present, so a remote SSHD can (if it wanted) demand to see signed evidence of user presence or refuse login, and I think a SSH agent can't fake that without help from the FIDO authenticator itself.
- staticassertion 6y agoOh duh, of course. Yes please confirm! Super eager to hear if this is the case.
- jlgaddis 6y ago
- dboreham 6y agoI've waited 10 years for this.
- StavrosK 6y agoSame here, and I just absolutely love how well it works. Now if Android SSH apps add support for it, my SSH life will be complete.
- ta17711771 6y agoCan you do it with Termux or T-UI somehow? Addons?
- StavrosK 6y agoHmm, I don't think so, but I'll look into it, thanks!
- xaduha 6y agoShould've asked around, there were devices, standards and software for this kind of thing for a while e.g. https://github.com/philipWendland/IsoApplet https://github.com/philipWendland/IsoApplet
- knorker 6y agoWaited 10 years? Why didn't you just use a yubikey in PIV mode, or the yubikey with gpg, or a smartcard, or… I've been using a yubikey PIV for, hmm… at least 5 years. Sure, a FIDO key is cheaper.
- closeparen 6y agoOpenSSH doesn't do X.509, how would PIV mode or a smartcard help?
- Xylakant 6y agoYubikeys work in PIV mode with openssh, it just requires the necessary module and some invocation dance with ssh-agent https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PKCS11.html https://developers.yubico.com/PIV/Guides/SSH_with_PIV_and_PK... or Filippo Valsordas yubikey-agent https://github.com/FiloSottile/yubikey-agent https://github.com/FiloSottile/yubikey-agent
- Bedon292 6y agoAm I missing something? The commands for resident and non-resident appear to be identical. Edit: They fixed it.
- arianvanp 6y agothey have the addition of -O resident from ssh-keygen: resident Indicate that the key should be stored on the FIDO authenticator itself. Resident keys may be supported on FIDO2 tokens and typically require that a PIN be set on the token prior to generation. Resident keys may be loaded off the token using ssh-add(1). from ssh-add: -K Load resident keys from a FIDO authenticator
- nobodyshere 6y agoCan't make that part work on Mac.
- StavrosK 6y agoUnfortunately, MacOS still ships with SSH 8.1, AFAIK.
- nobodyshere 6y agoI installed 8.3 through homebrew but its agent just doesn't allow me to do that. Also can't ssh-add an sk key.
- StavrosK 6y agoHmm, are you sure you aren't calling the agent of the old one?
- StavrosK 6y agoI had the same command in both by mistake :/
- spiridow 6y agoI'm really excited to see more and more people talk about FIDO2. If you're interested about this topic, I gave a talk about it yesterday: https://news.ycombinator.com/item?id=23689606 https://news.ycombinator.com/item?id=23689606
- StavrosK 6y agoThat's very useful, thank you! I've been looking for something that goes into a bit more detail, so your talk is timely.
- jjoonathan 6y agoHere's a browser compatibility matrix (I know, OP is about SSH). FIDO2/U2F Just Works in: Chrome on Windows Firefox on Windows Chrome on Mac Firefox on Mac Chrome in Ubuntu 20 Firefox in Ubuntu 20 Wall of shame (FIDO2/U2F does not Just Work in): Safari EDIT: it does work out-of-the-box in Ubuntu 20, my bad.
- microcolonel 6y agoJust Works in Chromium and Brave on Arch Linux.
- jjoonathan 6y agoWith or without udev tweaks? That has been the major caveat on linux in recent times.
- microcolonel 6y agoI have no personal udev rules for my Yubikeys, just whatever ships with Arch.
- xenophonf 6y agoI haven't had any problems using my Yubikey in U2F or PIV modes on Ubuntu 20.04.
- simias 6y agoI've been using my Yubikey in GnuPG smartcard mode for years to do the same thing, from what I can see from this tutorial FIDO2 seems a bit easier to setup initially but it also seems much less widely supported at the moment. Are there other tradeoffs to consider?
- StavrosK 6y agoI think those are pretty much the only ones, the Yubikey in GPG smartcard mode was always too fiddly for me and interfered with my agent in other ways, but this is trivial to set up and use. Also, a big draw of the USB SSH key for me is that I can plug it in to other computers and connect to my servers, which smartcard mode didn't do, so that was a big drawback for me.
- RL_Quine 6y agoYou can't do that easily, you still need the public key file on disk.
- StavrosK 6y agoNot with resident key mode.
- simias 6y agoYeah fiddly is the right word, although once the painful initial configuration is done it generally works fairly well in my experience. Being able to easily migrate to a new computer sounds like a great feature though.
- DCKing 6y agoEDIT: I misunderstood the post, and what I describe below is not true! I'm incredibly excited about FIDO2, but this is quite underwhelming honestly. I'd like to SSH with a credential on my Yubikey, not by a credential or configuration already stored on my computer that is unlocked by my Yubikey. I'd like to be able to plug in my Yubikey anywhere and go. My Linux desktop, my Macbook, my Windows desktop, my Android phone. - Yubikey with GPG/PIV for SSH: your Yubikey stores your private key. You can take it anywhere, plug it in, [have to go through all the setup required for your computer to talk GPG/PIV], and log in. - Yubikey with FIDO2 for SSH: your Yubikey stores a symmetric key to unlock your private key on your computer. [You cannot take it anywhere], plug it in, don't have to set anything up if your client and server have this (eventually), and log in. FIDO2 is solving a lot of authentication convenience problems, but not this one I think. I get that this pretty nice when integrating with Windows Hello or Apple's TouchID, but I don't think FIDO2 USB key with SSH is that great.
- notaplumber 6y agoYou can, that's exactly what resident keys in this article is referring to. Once all of those platforms have a more recent OpenSSH, you can ssh-add -K to add keys to your SSH agent.
- DCKing 6y agoI fully understand what kind of credentials FIDO2 can store - but as I read it this still requires manual configuration on individual devices.
- notaplumber 6y agoNope. It's in the article. Just insert the key and ssh-add -K. I wouldn't be surprised if other SSH agents (e.g. Apple) added a UI to do this.
- StavrosK 6y agoYou misunderstand how FIDO2 works. Read the article, it details how to do exactly what you say it can't. You can resume your excitement now!
- decentralbanker 6y agobeen looking forward to seeing FIDO gain traction for more use cases. i interviewed at a company where there's work being done on a FIDO-enabled smartphone approach: https://www.hypr.com/passwordless-ssh-linux-fido-login/ https://www.hypr.com/passwordless-ssh-linux-fido-login/
- j88439h84 6y agoIs this instead of typing a password to unlock the ssh key?
- Freak_NL 6y agoIf you wish. You can decide if you want a passphrase on the generated key or not, just as you can with a classic SSH key. It's probably best to use a passphrase and have ssh-agent remember it for you until you shut down the computer. That way you enter your passphrase the first time using SSH with that key after logging in, and ask you to tap the physical U2F key, and only ask for the interaction with the physical key afterwards. When I SSH to a host configured like this, the Yubikey U2F key I am using blinks to ask me to touch it. It's really quite neat.
- indigodaddy 6y ago@StavrosK do you have a writeup on how you put together your blog infrastructure?
- StavrosK 6y agoNot really but it's just Lektor and Netlify, hosted on Gitlab. I also have Gitlab CI deploying the site on Neocities (https://neo.stavros.io/ https://neo.stavros.io/) as a backup/just to see if I could.
- graton 6y agoI was able to get this going, but it took awhile as I use a non-standard working mode. All of the docs I have read assume that you are logged in locally on the system, but if you are not (like me) then things fall apart. I am running a Windows 10 desktop, and then SSH into my local Linux box from Windows. Both systems are sitting next to me and I can press the Yubikey easily. My local Linux system is running Fedora 32 and I did the following to enable a user connected via SSH to use the Yubikey. Created a user group for yubikey users, which in reality only has me in it. Created a /etc/polkit-1/rules.d/99-pcsc-yubikey.rules file which gives smartcard access to the 'yubikey' group. Without this then 'ykman list' would not work. Created a /etc/udev/rules.d/99-yubikey.rules to give access to the 'yubikey' group. I used /lib/udev/rules.d/69-yubikey.rules as the starting point for my file. I had to add my two Yubikeys USB IDs (lsusb to see them) as they weren't present. Made sure to log out and back in to have the 'yubikey' group be active for my user. I vaguely remember a command that would do it, but I forgot it. After all of that I got it to work :)
- ptspts 6y agoI managed to make this work today as described in the article, after installing and configuring the software dependencies. Client-side hardware dependencies: * USB token with U2F (FIDO) support. FIDO2 is optional. Any old YubiKey or similar will work. * For the resident key feature only: USB token with FIDO2 support. * To avoid confusion, only a single USB token should be connected when ssh-keygen is run. (When ssh is run, multiple USB tokens work, the user can touch the wrong one many times, and authentication succeeds after the user touches the right one.) * ED25519 support in the token is optional. (`ssh-keygen -t ecdsa-sk ...' uses the NIST P-256 curve, which works with all U2F tokens.) Client-side software dependencies: * For communicating with the token over USB, OpenBSD or (Linux with udev). * OpenSSH 8.2p1 or later. * OpenSSH client (ssh) compiled with `configure --with-security-key-builtin'. Without this, eventually authentication will fail locally with `internal security key support not enabled'. It's possible to work around this by compiling an .so file and specifying it with `ssh -o SecurityKeyProvider=....so', but it's complicated. Server-side software dependencies: * OpenSSH 8.2p1 or later. * Default OpenSSH server (sshd) settings (without PubkeyAcceptedKeyTypes), or PubkeyAcceptedKeyTypes in /etc/ssh/sshd_config containing sk-ecdsa-sha2-nistp256@openssh.com and (optionally, for ed25519-sk keys) sk-ssh-ed25519@openssh.com .
- ptspts 6y agoFYI Another client-side software dependency: libfido2 >=1.3.0. It doesn't work with libfido2 1.2.x or earlier. Also, if it doesn't work on your client system only because OpenSSH 8.2 was compiled without `configure --with-security-key-builtin', here is how to make it work: https://github.com/pts/external-sk-libfido2 https://github.com/pts/external-sk-libfido2