5 ms·
As an alternative, you might consider using an ed25519-sk ssh key so you can use your YubiKey as a second factor during authentication. I've got my keys loaded
by XiS 4y ago
As an alternative, you might consider using an ed25519-sk ssh key so you can use your YubiKey as a second factor during authentication. I've got my keys loaded up in the SSH agent by KeepassXC when I open my database and can log in to a box just by pressing my YubiKey. No keys on disk, no passwords to remember (except your Keepass master key ofcourse).
- tomaslaureano 4y agoWould love to know more about this workflow!
- XiS 4y agoIt's pretty much a combination the following: - https://keepassxc.org/docs/#faq-ssh-agent-how https://keepassxc.org/docs/#faq-ssh-agent-how - https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht... You could probably also put the SSH key itself as a resident key on the YubiKey. But personally I like the fact the key and 2FA aren't on the same device (and the fact you can only get my key when you know the KeepassXC master password).