3 ms·
Can this be "emulated" on macOS with the keychain?
by MillionOClock 3y ago
Can this be "emulated" on macOS with the keychain?
- tpmx 3y agoOn a modern Mac with secure enclave doing "ssh-add -K /path/to/private/key/file" and entering the passphrase once does this. It's really neatly implemented. From "man ssh-add" on a Mac: -K Load resident keys from a FIDO authenticator. No third party tools are needed.
- heavyset_go 3y agoYou can also use the `-K` flag without specifying a path if you store your SSH key on the security key itself.
- tpmx 3y agoIs this the way to go, and if so why?
- heavyset_go 3y agoLike anything, there are tradeoffs between them. You can store an SSH key on the security key itself, and you can use it on any machine you want without needing a corresponding key handle file. Downside to this is that anyone who has your security key potentially has your SSH key. If you use non-discoverable keys, you need a corresponding key handle to use SSH with your security key. That key handle can be treated like any SSH key, in that you can password protect it and use many rounds of PBKDF2 to secure it. Without that handle you can't use the security key for SSH. The first method requires you to enter your FIDO password any time you need access to the key, along with touching the authenticator. Using the second method, you can use a keyring to store your key handle's password and/or use an SSH agent, and you potentially just need to unlock it once with a password, then you only need to confirm via touch when you want to use the key.
- keybits 3y agoSecretive might be what you're looking for: https://github.com/maxgoedjen/secretive https://github.com/maxgoedjen/secretive