Using a Yubikey as smartcard for SSH public key authentication
undeadly.org
undeadly.org
This also helps immensely when you want to retire a key, whether due to loss of control or concerns about its strength in the future. Being in the practice of having a set of authorized keys, you can safely remove older ones from authorization lists without locking yourself out.
It does mean you have to get better at keeping your public key lists up to date, so that revoking a key doesn't need a bunch of manual steps. But that's something Ansible/Chef/Puppet are good at.
I make sure to use good labeling to know which key is on which device (user@hostname) to deprecate them when they get decommissioned.
https://cackey.rkeene.org/fossil/artifact?ln=on&name=f9156a5...
Note that the PIV approach used in the OP does not support RSA4096, while the OpenPGP approach does (since Yubikeys support RSA4096 in OpenPGP mode but not in PIV mode).
That carries over for SSH: in the most strict touch-mode, a separate touch is required for each authentication attempt. This requirement holds true even if you were to forward your SSH agent to the remote host: SSHing from there to another system would require another physical touch.
(not sure about the SSH agent forwarding as I haven't tested that, would be surprised if it worked without a physical touch)
Basically I don't see the differences you describe in day to day usage at all.
Disclaimer: I work on Solo key, we’re thinking to what’s the best way to support ssh.
What's much more important for me is the underlying capabilities -- a key which supports rsa4096 is great, a key which supports curve25519 in some fashion would be incredible.
Definitely curious for making it work like this. The last time I looked at it, I could make it require touch/PIN the first time the GPG key was used, but after it got loaded into gpg-agent, it continued to work for the lifetime of the agent w/o PIN/touch. That said, I'm entirely willing to admit the possibility I missed the right flags to do what I wanted.
I do like n =/= 1 in general (I've provisioned some yubikeys where the person using the key doesn't have the admin PIN, and so I like to give myself a bit more buffer before I have to meet up with them to unlock the key, but for my own keys, n == 3 would be totally fine.
I use my yubikeys as ssh keys and it's awesome, id suggest anyone who does should use the "cached" touch policy as you can then connect to many servers within the 15 seconds without having to keep tapping (good for ansible runs!)
Mac users can just brew install opensc but you'll need to link/copy opensc-pkcs11.so into /usr/local/lib
On Windows you can use the pageant agent from https://risacher.org/putty-cac/ and combine with weasel-pageant if you wish to use it as your ssh-agent in WSL https://github.com/vuori/weasel-pageant
I have a U2F key from NXP that works very well as a 2nd factor auth for my email account, however, I'm having a really hard time finding documentation on how to use it to store my ssh private key.
I just did `brew install opensc` and though it'd probably magiically work form there, but no luck.
The things a FIDO token / Security Key knows how to do are not really sufficient to authenticate with SSH public key Auth mode.
Specifically FIDO tokens know how to magically create a new public key and a cookie and promise they can subsequently sign specific messages that prove they know the private key if given back the cookie.
This is a very narrow feature set, deliberately to support the U2F / WebAuthn process only.
Someone could add a completely new SSH Auth method that works with this but the existing SSH public key method requires that you start by claiming "Hey, I know this key, can that work?". Whereas a FIDO token may not (and yours doesn't) even be able to tell anyone which keys it "knows" (because in fact it doesn't really know them at all, they are effectively encrypted inside the cookies it relies on, but only it knows how to decrypt those!).
yy () {
opensc_path="$(readlink -f $(brew --prefix opensc))/lib/opensc-pkcs11.so"
eval $(ssh-agent -P $opensc_path)
ssh-add -s $opensc_path
}I would like to understand the 'remove device and computer locks' hooks. And OSX integration.
Happy it works. Definitely want to try it myself.
When you have opensc installed it will detect your yubikey as a smartcard and ask if you want to unlock your computer with it
:edit: you also need to go to System Preferences > Security & Privacy > Advanced > Turn on screen saver when login token is removed