> 2FA for ssh
Correct me if I'm wrong, but isn't this what password-protected private key encryption is?
Correct me if I'm wrong, but isn't this what password-protected private key encryption is?
2FA would be private key (password-protected) and a separate (most likely one time use) password. Something you have (key that you decrypted) and something you know (the one-time password).
Keys are easily (and persistently) added to ssh-agent, at which point it is easy to forward and will generally silently authorize without any further user interaction. That reduces it to a single factor.
Compare that to a totp challenge or a yubi key plus a password. Having one of them won’t get you the other.