14 ms·
How to Store an SSH Key on a Yubikey
- xvector 4y agohttps://github.com/FiloSottile/yubikey-agent https://github.com/FiloSottile/yubikey-agent has worked really well for me in the past.
- xaduha 4y agoYou don't need this for ecdsa keys, normal ssh agent works just fine as in `ssh -A`.
- vladvasiliu 4y ago> As of OpenSSH 8.2 (Feburary 14, 2020) you are able to store an SSH private key on a yubikey! Here's how to do it. Many systems still don't have OpenSSH 8.2 (Windows 11, older debian stable, etc). For those, another solution is to use the PGP applet of the YubiKey, which exposes a regular RSA key. This guide has worked well for me: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide You can jump to the SSH sections if that's all you're after. There's a missing piece for Windows, since the agent coming with WinGPG won't be reachable by SSH. Some guy on GitHub put out a workaround, but I can't find it right now. -- edit: The workaround for Windows is this one: https://github.com/rupor-github/win-gpg-agent https://github.com/rupor-github/win-gpg-agent
- Denvercoder9 4y ago> older debian stable A bit pedantic, but what's currently "Debian stable", Debian 11, has OpenSSH 8.4. The previous release, Debian 10, has OpenSSH 7.9, but it is no longer called stable (instead, it's sometimes called "oldstable").
- ylk 4y ago> which exposes a regular RSA key With newer Yubikeys you can also use ECC PGP keys: > Support for Elliptic Curve Cryptographic Algorithms have been added to the YubiKey 5.2.3 and above firmware. https://developers.yubico.com/PGP/YubiKey_5.2.3_Enhancements_to_OpenPGP_3.4.html https://developers.yubico.com/PGP/YubiKey_5.2.3_Enhancements...
- knorker 4y agoNot to mention all the network appliances in the world. While this only works for a subset I'll stay with my RSA key in PIV mode on yubikey. Works great.
- jve 4y agoAnother solution for windows: The support is already there within 8.9.1.0 beta release: https://github.com/PowerShell/Win32-OpenSSH/releases https://github.com/PowerShell/Win32-OpenSSH/releases You must then use the SSH installed within 'C:\Program Files\OpenSSH\ssh.exe' and not the builtin within system32.
- enasterosophes 4y agoSomething else that is quite nice is that you can switch to certificate auth and use your yubikey to protect an ed25519-sk certificate authority.
- endre 4y agothis.
- stingraycharles 4y agoHow does that work, do you know a good tutorial for this?
- dnet 4y agoI made my own CA for this because nothing else could provide transparency regarding certificate issuance (whether an attacker issued a "spare" backdoor certificate) - source code: https://github.com/silentsignal/zsca https://github.com/silentsignal/zsca - my talk about the design and results: https://pretalx.hsbp.org/camppp7e5/talk/D3E9HN/ https://pretalx.hsbp.org/camppp7e5/talk/D3E9HN/
- enasterosophes 4y agoLook for a tutorial on ssh certificate auth, and use ed25519-sk keys for the CA.
- Diti 4y agoBut PIV only supports keys up to 2048 bits. :<
- enasterosophes 4y agoI didn't say anything about PIV. The article I was replying to is talking about sk keys, and so am I.
- nextlevelwizard 4y agoI know Yubikeys are pretty old hat by now, but I still feel weirded out by relying something like this into a USB stick. I just know I would lose the key at some point locking me out from everything. Of course the solution is to have two keys, but don't really know where I would feel comfortable storing the extra key (also how often do you check that it still works?) I'm probably just over thinking this and overly paranoid.
- stingraycharles 4y agoAs someone who uses Yubikey for about 5 years for SSH, GPG and O2F, an extra key is indeed the solution I use. Effectively it means all integrations must support multiple keys, and you’ll have to register both. Of course, this doesn’t work everywhere, such as AWS. In those cases, I typically use my “main” key. I’d argue that the key breaking due to wear or being lost is less of a risk than human error: just last week I had to enter the admin GPG code for the first time in years, and I forgot it initially, which caused the device to lock itself, and apparently the recovery code didn’t work. Caused me a few hours of stress to get it resolved. So yeah it requires some discipline. What’s important is that you need to identity the services you absolutely cannot lose access to: in my case it’s my email and password manager. For those two, I properly manage backup codes, regularly test both yubikeys, etc. The rest can all be recovered through email, if it needs to be.
- artdigital 4y agoI have a question - do you disable regular OTP 2FA on services you use the Yubikey? I have one too and religiously added it to all kinds of things, but each service allowed me to just skip the yubikey when a regular OTP code was entered, effectively making me not use the yubikey
- rgoulter 4y agoIf you have only one Yubikey, and use it as the only factor of authentication to a website, you'll need to ensure you store the 2FA recovery codes safely. Whereas, if you have both Yubikey and TOTP as factors of authentication, if you lose the Yubikey, you'll still be able to login. I view that as "Yubikey more convenient than TOTP". You can either use TOTP, or the Yubikey, and it's easier to tap a button than to enter a code.
- sandreas 4y agoFor those who like to know more details about Yubikeys, I found this pretty interesting: https://www.youtube.com/watch?v=INi-xKpYjbE https://www.youtube.com/watch?v=INi-xKpYjbE
- tazjin 4y agoThe problem with this approach is that the `-sk` keys need to be supported server-side (I'm not sure if that support goes beyond including them in a list of recognised key types, but it doesn't matter). As a result, lots of systems that are not bleeding edge still don't accept them, for example Gerrit.
- tialaramex 4y agoThe support is substantially more than "including them in a list of recognised key types" because the FIDO device is deliberately unwilling to do anything except emit FIDO-style signatures, so you need to understand those signatures and verify them. On the other hand, probably we should have learned by now that even apparently trivial verification steps are too easy to get wrong (or plain omit) and so you really want to delegate all of this work to just one implementation which was actually written by people who know what they're doing and, preferably also formally verified as correct since people who "know what they're doing" still make far too many mistakes. Thus, maybe there shouldn't be so many independent (and likely in some cases, wrong) implementations of this check.
- moontear 4y agoOT: what kind of date format is used in the article? It says „M05 27 2022“ and I have not seen that before. Does M05 mean May-05, so basically saying may-may?
- cgio 4y agoM for month?
- ikornaselur 4y agoI guess it's to clear the confusion of, for example, what date would "04 07 2022" be, is that 4th of July or April 7th? "M05 27 2022" seems to indicate that it's in fact MM DD YYYY not DD MM YYYY
- Sharparam 4y agoIf only there was some kind of international standard for date formatting we could use to get around that issue...
- xena 4y agoOwner of the blog here. I use the same date format on my website as I do on my phone: https://twitter.com/theprincessxena/status/1531240367600852992 https://twitter.com/theprincessxena/status/15312403676008529...
- jopsen 4y agoCurious, if you delete the stub in ~/.ssh/id_ed25519_sk, can you then recover the key? Or does the on-the-fly key generation use random bytes stored in the stub?
- xaduha 4y agoI suggest testing it yourself in any case, I don't think this article is correct in this. I did try it in the past with Google Titan and not a Yubikey and I could be wrong. EDIT: `-O resident` might be what is doing it though, I wasn't aware of this option.
- TimWolla 4y ago> EDIT: `-O resident` might be what is doing it though, I wasn't aware of this option. Indeed. This will use FIDO 2 Discoverable Credentials / Resident Keys. Those are fully stored on-key (but their number is limited): https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Guide/Resident_Keys.html https://developers.yubico.com/WebAuthn/WebAuthn_Developer_Gu.... Non-resident keys will basically give out the private key encrypted with a static master key as the key handle and thus support an unlimited number of keys. If you lose the key handle, then the key is gone. That's probably what you were experiencing with your Titan.
- jopsen 4y ago> Non-resident keys will basically give out the private key encrypted... I thought U2F took a random string from the caller and derived the private key that..
- seodisparate 4y agoYou can use a GPG key stored on a YubiKey with openssh, but with some caveats: 1. gpg-agent must act as your ssh-agent (which means ssh-agent should be disabled and replaced by gpg-agent). 2. If using `pinentry-curses` (YubiKey usually permits access to the contained GPG key via the use of a pin), you must have `export GPG_TTY=$(tty)` (or your shell's equivalent of setting the GPG_TTY environment value to the output of `tty`). 3. You can fetch the public key of your GPG key with `ssh-add -L` (gpg-agent must be acting as your ssh-agent, and the YubiKey with the GPG key has to be plugged in). 4. You must have the line `enable-ssh-support` in your `$GNUPGHOME/gpg-agent.conf`. I used a guide[1] to set up a GPG key on to a YubiKey, and for those who don't want to use GPG, the guide also has a section[2] about just using an SSH key as well. [1]: https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide [2]: https://github.com/drduh/YubiKey-Guide#ssh https://github.com/drduh/YubiKey-Guide#ssh
- NormenKD 4y agoI am using this setup for a while now and would like to tell everyone about an advantage in contrast to the 'resident key': You can push a single, identical key to two YubiKeys, making it easier to recover. Resident keys are (partially?) created on the hardware token and thus can't be replicated. The GPG keys can be pushed to a couple of YubiKeys before you delete them forever (or keep a paper backup somewhere safe).
- archi42 4y ago> This should work on other FIDO keys like Google's Titan, but we don't have access to one over here and as such haven't tested it. For my trusty HyperFIDO Mini (usb id 0x2ccf:0x0880) this doesn't work, though it's rather old (1st gen) and maybe they refreshed it to support this. ssh-keygen fails with "Key enrollment failed: requested feature not supported". I wanted to replace it with a USB-C (& maybe NFC) device anyway, so seems like a good opportunity.
- tialaramex 4y agoThe feature causing this is -O resident which tells the device, "Hey, you need to remember these credentials" (ie they are resident on the device). For WebAuthn this enables "usernameless" login. You rock up to a random PC anywhere in the world, go to example.com, just click "Sign in", and your authenticator is like, "Hi example.com, according to my records I am archi42, user 123456-ACBDE-123 and as proof here's a signature made with my unique private key" and the site checks its database and signs you in. Convenient and fairly secure (most devices with such a feature expect a PIN, or a fingerprint, or some such factor beyond "something you have" in the form of the authenticator itself). For SSH, this means the magic file that makes SSH with FIDO work can be regenerated on another client machine by just asking it to spit out the credentials. Chances are your device does not have this feature, usernameless login on the web is rare, so few people need this, and of course it's a considerable extra hardware implementation burden. Yubico products have it though, as do some others, and the phone implementations (iPhone, newer Android) likewise. If you mostly use the same machines (laptop, maybe a desktop) for SSH, the resident feature isn't important, just don't write "-O resident" and remember that although they aren't a security feature the resulting files are unique and if you don't have them you can't log in. If you regularly use different machines for SSH login because you're say, a roaming technician logging in to physical hardware on site or you insist on travelling very light, then it's very valuable and worth upgrading to get the resident feature.
- archi42 4y agoThanks, I appreciate the effort you put into the answer; though I know how ssh keys work and the basics about FIDO as well ;-) I got the hyperfido 5 years ago and doubted they're still selling the same hardware today. I exchanged a few mails someone from their C-suite back then on the topic of using the keys for SSH, and it wasn't easily possible back then (also: he seemed very nice [cue Canada meme], so I didn't want to spread falsehoods about the company on HN). Actually I checked right now, and their current offerings seem to support FIDO2 (also: the model number & name changed slightly). So I suppose their current generation should work. //edit: ah, your pointer was still worth the effort. I tried non-resident and ecdsa-sk works with my key (but not ed2219-sk). I still need a new key because I want to have a resident key :)
- ChrisMarshallNY 4y agoWhat I would love, and it has not been supported (I was basically told “Go away, kid. Yer bodderin’ me!”, when I suggested it to AgileBits), is the ability to store the local 1Password vaults onto a separate volume from the main one. I have a small encrypted disk image that I mount, after booting my computer. A YubiKey would be similar. I use this to store my really critical stuff. I don’t back up the mounted disk, but do back up the encrypted image.
- Raed667 4y agoHave you tried using the "export" feature?
- ChrisMarshallNY 4y agoThat’s different. The shared hosted vault is better (and works great). I’m talking about a “set and forget” version, where 1Password doesn’t work at all, unless the volume is mounted. I tried using symlinks or aliases, but that did not work. 1Password simply created a new vault.
- ndsipa_pomu 4y agoIs it possible to do something similar with an NFC smart ring? I'd be much less likely to lose a ring than a Yubikey.
- bschne 4y agoAre there any best practices on using one of the "-sk" key types and authorizing usage with your security key, vs. storing the whole ssh key on the security key?
- fmajid 4y agoYubikey Manager is not needed to use ed25519-sk keys. They use only FIDO U2F functionality, so cheaper USB keys ($29 for a Yubico Security Key USB-C NFC vs $55 for the full Yubikey 5C NFC). They are thus not limited to Yubico's proprietary functionality controlled by Manager, which has a wider attack surface than I am comfortable with, and are not limited to platforms running the Yubikey Manager software (e.g. on OpenBSD). Since the key has never been outside the USB enclave, there is no way it could have been surreptitiously copied, e.g. if there was a rootkit on the machine where the key was generated before copying to the Yubikey.
- netfortius 4y agoIt's actually even cooler to store them on a Ledger device
- KelvinAnderson 4y ago
- nyanpasu64 4y agoI tried ed25519-sk keys last year, but abandoned them when GitLab wouldn't recognize their public keys. It seems that as of 3 months ago GitLab has added support (https://gitlab.com/gitlab-org/gitlab/-/issues/213259 https://gitlab.com/gitlab-org/gitlab/-/issues/213259) so I should give them another try.
- a-dub 4y agobut wait a minute... this is just storing the private key material on the yubikey like any storage device and it is loaded and copied right off every time you use it, right? doesn't that defeat the point of using a yubikey where the private key itself is never read from the device during authentication?
- xena 4y agoAuthor of the article here. From what I understand it puts the private key material on the Yubikey itself and then during the signing part of SSH authentication the SSH client asks the yubikey to do the signature. The private key never leaves the device.
- a-dub 4y agothat's how i would hope it would work, but isn't the key in this example getting loaded into the agent?
- zrail 4y agoThe agent is a shim that talks to the Yubikey.
- a-dub 4y agointeresting, just read through the release notes. pretty cool. i think a small discussion of this (and how the agent/key handles/resident mode work) would make an excellent addition to the blog post. it was very clear how to set it up, but left me with questions as to if i should... in practice i would wonder about backup authentication methods and key rotation.... but otherwise all in all pretty cool.
- sbf501 4y agoCan you also include a screen shot of the ssh connection process? The article stops abruptly at the most interesting part: using the key.
- 4y ago
- veganjay 4y agoThanks for sharing the article. I followed it and it was very simple to set up. In the past, I postponed setting this up after I encountered issues. I tried to run "ykman", but it seemed to fight with "yubioath-desktop". It was tricky to debug and I ended up rebooting. I think the reason was that I installed "yubioath-desktop" using snap, which runs "pcscd" as a snap service, and "ykman" wants to start the "pcscd" system service. Either case, for this tutorial, I skipped the part running 'ykman'. Basically the only commands were: ssh-keygen -t ed25519-sk -O resident ssh-add -K
- WhyNotHugo 4y agoYubikeys (and similar hardware tokens) are a blessing for authentication. I use them for SSH, but also for 2FA on the web, `sudo` and a few other items. Wrote about it recently here: https://hugo.barrera.io/journal/2022/05/07/how-i-secure-my-setup-with-a-yubikey/ https://hugo.barrera.io/journal/2022/05/07/how-i-secure-my-s...
- jve 4y agoWhile we're at this - is there anyway for sudo NOT to ask for password when logged in via key authentication?
- rgoulter 4y agoI'd expect the keywords "linux PAM" would be your friend when looking for this. https://wiki.archlinux.org/title/PAM https://wiki.archlinux.org/title/PAM
- veganjay 4y agoIs there a way to show which SSH keys are loaded on the Yubikey? (It looks like you can store multiple) Also, how can one remove the SSH keys from the Yubikey? I've tried to find articles and SSH on the Yubikey gets very confusing as there seem to be so many techniques!
- vletal 4y agoIn the blogpost they give an example of exactly that $ ssh-add -L sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIKgGePSwpBuHUhrFCRLch9Usqi7L0fKtgTRnh6F/R+ruAAAABHNzaDo= cadey@shachi Seems like the key is exposed as ssh agent.
- veganjay 4y agoThanks - "ssh-add -L" talks to the ssh-agent and asks what keys are loaded. That shows all keys including keys from the yubikey and from the local filesystem. I am looking for a command that shows what's on the yubikey. From what I gather, if the command from the article is run: "ssh-keygen -t ed25519-sk -O resident", the key is stored in a FIDO2 slot. If that's the case, my question is how to show what is in the FIDO2 slots and how to delete them?
- veganjay 4y agoFound it: Install ykman: https://github.com/Yubico/yubikey-manager#linux https://github.com/Yubico/yubikey-manager#linux Show FIDO2 credentials: $ ykman fido credentials list ssh: 0000000000000000000000000000000000000000000000000000000000000000 openssh Delete: $ ykman fido credentials delete CREDENTIAL
- gwbas1c 4y ago> such as the Tongues you received as a kid when you were forced into learning the bible against your will Wait, what? My wife stopped going to Awanas when some leader told her she was going to hell for not learning the Bible verses. Later I learned that her father was pissed off about the whole situation.
- spike021 4y agoAs someone who was in an Awana...club(?) for most of my childhood, I never had this happen. That sucks. Some people are way too crazy.
- sbf501 4y agoI dated a charismatic christian who did the whole laying-hands on thing and speaking in tongues as a kid. Weird stuff. But not any weirder than any other religion system comparitavely.
- veganjay 4y agoSome additional information: - https://www.yubico.com/blog/github-now-supports-ssh-security-keys/ https://www.yubico.com/blog/github-now-supports-ssh-security... - https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht... - https://developers.yubico.com/SSH/ https://developers.yubico.com/SSH/ The second link describes the advantages/disadvantages of non-resident vs. resident keys.
- markstos 4y agoUnless I've missed something, SSH keys stored on Yubikeys are still hampered because you aren't allowed to a touch policy of "touch never". Imagine needing to touch the Yubikey with each "git pull" or using Ansible to operate over SSH on a dozen servers in parallel, and needing to touch the Yubikey once for each server. The feature request I'm tracking is here: https://github.com/FiloSottile/yubikey-agent/issues/95 https://github.com/FiloSottile/yubikey-agent/issues/95 The proposed feature would allow setting a touch policy for the SSH key.
- xena 4y agoIf you use SSH ControlMaster sockets, it's not so bad in practice. It can be a pain at times, but I think the security is worth it.
- jazzythom 4y agoWait is generation on the host? Nonono you generate a GPG key on the key then export the public key and derive the SSH key. These instructions are wrong the host never should store the key even if airgapped
- xena 4y agoDoing that means I have to use GPG. I am not paid enough to use GPG.