The best way to store SSH private keys is in a hardware security module, or HSM.
I have three Yubikeys. Would I need to add three ssh keys to every one of my ssh accounts?
I have three Yubikeys. Would I need to add three ssh keys to every one of my ssh accounts?
If one Yubikey were lost, stolen, or damaged, you would then revoke its access by removing the corresponding entry in ~/.ssh/authorized_keys.
One upside though is that all your keys can go as individual lines in authorized_keys, so there is still only one file to install on remote machines.
This is the guide I followed: https://github.com/drduh/YubiKey-Guide