I'm also curious what people's preferred fallback method is for preserving access to machines if you lose access to your yubikey(s), assuming you keep your private SSH key stored on one.
I'm also curious what people's preferred fallback method is for preserving access to machines if you lose access to your yubikey(s), assuming you keep your private SSH key stored on one.
It's a central place where you can do your logging, which many enterprises must do for compliance reasons.
I've found many compliance standards to be pretty open-ended and function-driven, rather than prescribing specific standards. Client contracts.... they may be a different beast, and often require specific promises by vendors.
Now, you could try to implement that on the systems themselves, but how do you establish a mechanism that logs actions of an administrative user, and at the same time cannot be disabled by the same administrative user?
So instead you use a shell control box as a bastion, and regular administration of the target hosts don't have root access to the shell control box, so they cannot circumvent logging.
I haven't yet any standards that explicitly demand bastions, but it seems to be one of the standard implementations that have proven to pass audits, and so it's a pretty low-risk implementation of the logging requirements.
Later
Sorry, I see below you're thinking about using Yubikeys in addition to keypairs. This obviously doesn't answer that question.
We’re doing this successfully where I’m working.
This looks like exactly the answer I needed; thank you!
This doesn't require any support on the serverside; as far as the server's concerned, the Y4 is just another RSA key.
It does require the more expensive Yubikey, but there are some security advantages to using it.
I would be interested in how you think U2F with SSH is doable. Maybe with a custom SSH server and client?
Have you actually see this done in anger?
Bastions are nice, because you can harden them, or put 2fa on them, and not worry as much about the ssh config on the other hosts -- just make sure they don't accept ssh connections from the outside world.
It looks like there’s some benefits with bastion hosts around locking down commands & access in a fiber-grained way from vpn, but man what a pain in the ass. I can see a certain perspective that would really care to do things this way but VPN from my cold dead hands.