5 ms·
I love SSH, but I don't want to actually use SSH for this. That's not the important part. All I want is key-based authentication, and that doesn't need SSH.
by adamtj 12y ago
I love SSH, but I don't want to actually use SSH for this. That's not the important part. All I want is key-based authentication, and that doesn't need SSH. I want to be able to plug a security token into a USB port and be logged in, without even having to click a sign-in button. Reformat, reinstall, reboot, plug in security token, launch browser, type news.ycombinator.com and I'm already logged in.
- stephenr 12y agoI don't know if I'm missing something here, but it sounds like what you want is just SSL/TLS Client Certificates using PKSC#11 for the private key?
- e12e 12y agoWhich is also usable for authenticating to ssh (but needs to set up as such certs are different from ssh key and from ssh "native" certs).
- chubot 12y agoYou can do this with google products: https://support.google.com/accounts/answer/6103523?hl=en https://support.google.com/accounts/answer/6103523?hl=en You just have to touch the USB security token to have it release the key. I believe the idea is that malware can't really trick you into touching it, so it's more secure.
- Rafert 12y agoIt's works a bit different than 'releasing a key': http://fidoalliance.org/specs/fido-u2f-v1.0-ps-20141009/fido-u2f-overview-ps-20141009.html#site-specific-public-private-key-pairs http://fidoalliance.org/specs/fido-u2f-v1.0-ps-20141009/fido...