6 ms·
Yubikey is probably the sanest cross-platform solution. Assuming you're using an updated beyond Microsoft's default version, which you'll need to get from https
by Firehawke 5y ago
Yubikey is probably the sanest cross-platform solution. Assuming you're using an updated beyond Microsoft's default version, which you'll need to get from https://github.com/PowerShell/Win32-OpenSSH/releases https://github.com/PowerShell/Win32-OpenSSH/releases to have support for USB keys, of course. Hopefully MS will update their included version at some point soon.
From there, it's as simple as telling the .ssh/config file to use the key from your Yubikey and you can use the same config file on any machine you have OpenSSH.
- Xylakant 5y agoHave you done the setup on windows lately? Because AFAIK, (Fido) yubikey support is still missing. Using either the PKCS#11 support or the gpg applet requires some extra piece of software. Also it required telling git to use that specific ssh version, last time I tried a few month ago, the git installer defaulted to something bundled IIRC. Then, you also want to fiddle with autocrlf and other settings. Git on windows is a pain, but that’s not GitHub’s fault.
- Firehawke 5y agoYeah. I'm using it right now. After doing a single-time setup and making sure that I keep a backup of the .gitconfig, etc, I haven't had any problems. I made sure to point Git specifically to the OpenSSH I provided (which I keep in c:\utils\openssh) with the following bit in the .gitconfig file: [core] sshCommand = C:/utils/OpenSSH-Win64/ssh.exe For GPG, the only things I've done is to use gpg-agent and set up a passthrough for gpg-agent to WSL2 for both OpenSSH and GPG via https://github.com/BlackReloaded/wsl2-ssh-pageant/ https://github.com/BlackReloaded/wsl2-ssh-pageant/ since I do development both natively on Windows and via WSL2.
- Xylakant 5y agoSo it’s still as it was when I last set it up: everything is there, but it requires fiddling. I’m using a similar setup right now. One place where Linux has the better experience.
- csdvrx 5y ago> Because AFAIK, (Fido) yubikey support is still missing. Correct, hopefully Microsoft will provide an updated SSH client soon. It only requires recompiling OpenSSH with the correct flags. Alternatively, use these build instruction for openssh with FIDO for windows: https://gist.github.com/martelletto/6a7cf806c6433ac9ce71d66afb94d70e https://gist.github.com/martelletto/6a7cf806c6433ac9ce71d66a... > Using either the PKCS#11 support or the gpg applet requires some extra piece of software For those wanting to do that, here are some ways: Using a premade dll: https://github-wiki-see.page/m/mooltipass/minible/wiki/Setting-up-FIDO2-authentication-on-Linux-from-Windows https://github-wiki-see.page/m/mooltipass/minible/wiki/Setti... Or with a middleware: https://github.com/mgbowen/windows-fido-bridge https://github.com/mgbowen/windows-fido-bridge Using the Hello API: https://github.com/tavrez/openssh-sk-winhello https://github.com/tavrez/openssh-sk-winhello Given how many people came with their own ways, I believe there's enough demand for Microsoft to fix that.
- Xylakant 5y ago> Correct, hopefully Microsoft will provide an updated SSH client soon. It only requires recompiling OpenSSH with the correct flags. I checked when Microsoft-owned GitHub announced full Fido support, but I’ve stopped holding my breath.