3 ms·
A big problem I have with ssh carts is that they are not universally supported. For me, there is always some device or daemon (for example tinyssh in the initra
by anyfoo 6mo ago
A big problem I have with ssh carts is that they are not universally supported. For me, there is always some device or daemon (for example tinyssh in the initramfs of my gaming pc so that I can unlock it remotely) that only works with “plain old ssh keys”. And if I have to distribute and sync my keys onto a few hosts anyway, it takes away the benefits.
- TZubiri 6mo agoMight actually be a positive instead of a negative. Gaming use-cases should have not any effect on security policies, these should be as separate as possible, different auth mechanisms for your gaming stuff and your professional stuff ensures nothing gets mixed.
- nagaiaida 6mo agoremote unlock is also useful when you're not gaming so that feels like the wrong aspect to focus on
- anyfoo 6mo agoHah? It being my gaming machine has nothing to do with the problem. It’s also my FPGA development machine, though it gets used less for that. It only happens to be the only Linux workstation in my home (the others are Macs or OpenBSD).
- TZubiri 6mo agoIf you care about security, I recommend investing into a separate computer for developing hardware and software and another for downloading games on. You can setup your security any way you like, but nothing beats an air gap in terms of security and simplicity.
- namibj 6mo agoUpgrade to a better one in initramfs?
- AceJohnny2 6mo agoAdding to this: while certs are indeed well-supported by OpenSSH, it's not always the SSH daemon used on alternate or embedded platforms. For example, OpenWRT used Dropbear [1] instead, which does not support certs. Also, Java programs that implement SSH stuff, like Jenkins, may be doing so using Apache Mina [2] which, though the underlying library supports certs, it is buggy [3] and requires the application to add the UX to also support it. [1] https://matt.ucc.asn.au/dropbear/dropbear.html https://matt.ucc.asn.au/dropbear/dropbear.html [2] https://mina.apache.org/sshd-project/ https://mina.apache.org/sshd-project/ [3] I've been dealing for years with NullPointerExceptions causing the connection to crash when presented with certain ed25519 certificates.
- briHass 6mo agoYou can just replace dropbear with openssh on OpenWRT. That was one of the first things I did, since DropBear also doesn't support hardware backed (sk) keys. Just move it to 2222 and disable the service. I reenabled DB on that alt port when I did the recent major update, just in case, but it wasn't necessary. After the upgrade, OpenSSH was alive and ready.