macOS Sierra Stores and Syncs SSH Passphrases to iCloud
twitter.com
twitter.com
It's not useful though as you shouldn't share ssh keys between machines anyway.
Are you talking about public or private keys ? I see nothing wrong in using same public key to log in from a particular machine to a number of remote machines.
There is nothing really wrong with it; it's a good way to reduce the burden of managing secrets. The downside though is when multiple remote machines need to be contacted because a private key was revoked. Then again, a common need for revocation is a compromise of the machine on which the private key(s) is stored, which can often mean a number of private keys need to be revoked. I think the ideal is still to have unique key pairs for each client-server combination.
The most likely cases are that (1) the client machine was compromised, or (2) an un-encrypted backup was lost. In either case, I have a hard time seeing how one private key needs to be revoked but others on the same client machine don't.
I could ssh into a server without typing the ssh key password, but zsh refused to tab-complete scp and rsync command lines. Turns out it was using "ssh -o BatchMode=yes servername somethingsomething" to retrieve a list of files, but "-o BatchMode=yes" prevented whatever magic is happening from unlocking the ssh key. Figuring this out was tricky because dtruss and lldb refused to attach to /bin/zsh and /usr/bin/ssh because of SIP. (In fact, "dtruss --help" lists "dtruss df -h" as the first example, something that doesn't even work on sierra because /bin/df is protected by SIP)
The fix is to run "ssh-add -A" after booting. Very odd, since there are no password prompts involved anywhere.
One workaround is actually to just cp /bin/whatever to /tmp/whatever and debug that, but in this particular case I needed to follow forks (from zsh to ssh) so that wasn't as easy. Or I guess I could have played games with $PATH. Ah well.
Either way, there is something funny going on with ssh and private keys and their passphrases. Very odd how "-o BatchMode=yes" fails to load encrypted private keys that don't require any user input in normal use. And it's definitively something new because this was never a problem in 10.11 or below.
Edit: Ah, and another comment here provided the answer: https://news.ycombinator.com/item?id=12654917
In prior versions, it was stored in Login keychain, which was not synchronized.
Additionally, the items were visible in the security command line tool and in Keychain Access, so you could delete them.
The Local Items keychain / iCloud Keychain is a new style keychain that was back ported from iOS. The security and Keychain Access tools have no visibility into it, it's 100% handled by the secd service.
Edit: Ah, sorry, you meant in Sierra specifically. Yes. But I'll leave these clarifying details here for posterity :)
Edit2: Additional detail - in prior OSes, there was a GUI prompt asking if you wanted to store the passphrase in the keychain. This is gone now. It just does it (unless you preemptively edited the ssh config file to disable keychain storage in advance)
Edit3: Can confirm that "ssh-add -K -d" does in fact delete the passphrase from the keychain, even though it may throw an agent error.
That's not quite true: Keychain Access can write to Local Items keychain, but not everything in Local Items are visible to Keychain Access. Apple changed ssh to store private key passphrases differently than before, in a way that's invisible to Keychain Access. However, you can freely move / copy entries from, say your login keychain, to Local Items with Keychain Access, and vice versa, and they would remain visible.
Fortunately, the Local Items keychain, stored in ~/Library/Keychains/<UUID>/keychain-2.db is just a sqlite3 database, with (presumably) encrypted fields. If you run "ssh -vvv" you can even see the query.
> Edit3: Can confirm that "ssh-add -K -d" does in fact delete the passphrase from the keychain, even though it may throw an agent error.
Huh, I thought I'd tried that before resorting more drastic measures. Or maybe "-d" works but not "-D", hmm or maybe I'd neglected to also pass "-K".
http://apple.stackexchange.com/questions/253779/macos-10-12-...