4 ms·
For those not buying into 1password, what is the "correct" non-1password way to manage SSH keys?
by ents 5y ago
For those not buying into 1password, what is the "correct" non-1password way to manage SSH keys?
- Siecje 5y agokeyring?
- irl_ 5y agoSSH keys authenticate you. They are an identity. You probably don't need more than one or two identities (maybe personal and work). You can just get a couple of YubiKeys and configure the OpenPGP applet, or the PIV applet, with an authentication key/certificate and use that for SSH. Take the token with you and you've got some pretty strong authentication. More modern SSH servers will let you use U2F security keys in the same way, which are cheaper than the full YubiKey. I've learned recently that YubiKey has really good documentation for how to set up their tokens to achieve different goals, it would be worth reading their docs if you're considering getting a hardware token for your keys.
- deleted 5y ago[deleted]
- jillesvangurp 5y agoprivate key never leaves the device it is on; public key is .. well public so not something to store in a password manager. If the device is replaced, you create a new ssh key pair or restore your old one from a backup. In case your device is stolen/lost, you revoke access by removing the public key wherever you used it. This too is something a password manager can't do for you. If you are in a cloud environment, you let it manage keys for you. E.g. we don't provision any keys to GCP vms and instead login via a gcloud command that provisions temporary ssh credentials. In short, I see no need for using a password manager for managing ssh keys. The public key is not something that needs protecting. The private key is something that you should not share between multiple devices or generally pass around. But of course being able to paste your public key from some tool is nice if that is a regular thing in your life. And if you switch between multiple key pairs, it's probably nice to have something more user friendly than very fiddly command line tools. I guess the latter is what 1password is trying to solve here.
- ajnin 5y agoI don't know is that's "correct" bit what I use is KeePass with the KeeAgent plugin, which acts as an SSH agent. The keystore is stored on a nextcloud instance which allows to share the key easily between multiple hosts. It works flawlessly with git, ssh, also Windows tools like Putty will pick it up.
- qbasic_forever 5y agoLook into SSH certificates if you control the server, it's much better than littering public keys everywhere: https://smallstep.com/blog/use-ssh-certificates/ https://smallstep.com/blog/use-ssh-certificates/ Hashicorp's Vault provides a CA for SSH keys along with all kinds of other secrets and such, it's very commonly used in the industry.
- politelemon 5y agoKeePass2 + KeeAgent plugin. Or, KeePassXC which has an SSH plugin bundled.
- ghishadow 5y agohttps://www.funtoo.org/Keychain https://www.funtoo.org/Keychain in linux i use this, never had any issue, it can manage gpg keys too