4 ms·
It's actually very easy on linux now: You just use the two -sk key types released in Feb 2020 https://www.openssh.com/txt/release-8.2 https://www.openssh.com/tx
by boustrophedon 4y ago
It's actually very easy on linux now: You just use the two -sk key types released in Feb 2020 https://www.openssh.com/txt/release-8.2 https://www.openssh.com/txt/release-8.2
`ssh-keygen -t ed25516-sk` or `ecdsa-sk` and then you touch your yubikey when unlocking the key, the same time as you would type a password.
Question for anyone else reading: Does it make sense to use a password with -sk keys? I don't think it would make a difference either way.
- frutiger 4y ago> Does it make sense to use a password with -sk keys? I don't think it would make a difference either way. Only if you want to protect your keys from being used by someone that has access to the private key + yubikey (i.e. someone physically present). In other words, the -sk type private key is useless without the yubikey as well.
- boustrophedon 4y agoPhysical presence makes sense. I didn't really think it through but it's just the same as any other 2FA: you want something you know and something you have. Thanks.
- flemhans 4y agoAre there any Linux-friendly laptops with a TPM built in? It's nice not to have to rely on an external yubikey
- kitsunesoba 4y agoIt's not a perfect rule but anything a generation or two behind and has a GPU that's either integrated (Intel or AMD) or discrete AMD with Intel wifi and bluetooth are going to have a pretty good chance of handling a reasonably recent Linux distro (e.g. Fedora or Ubuntu non-LTS) well. While Nvidia provides official Linux drivers, I've personally had more trouble out of them than I have the stock Linux drivers for Intel and AMD GPUs. Any laptop that is listed as supported by Windows 11 will have an onboard TPM.