"Normal" SSH keys will work for (pretty much) all systems that support SSH. And the ones that don't will certainly never support U2F.
And even that is not true in all cases. I still regularly encounter devices that only support 2048 bit RSA and nothing beyond that. /glances in ubiquis direction.
Since I use Yubikeys in PIV mode with PKCS#11, it works just fine to use its 2048bit RSA.
If the option is 2048bit RSA, passwords, or software keys, then I know what I prefer.
For business, it's a better deal to buy new Yubikeys that support FIDO2 then it is to support GPG on Yubikeys.
I had a Yubikey 5 with the first firmware revision and resident keys worked fine.
Because the first firmware revision lacks the credential management API, there's no way to list the resident keys on the device or to delete individual keys. The only way to delete resident keys AFAIK is to reset the FIDO2 application on the key.
- The guide was mostly written before that was possible
- Many servers are slow to update to newer distro versions with newer openSSH versions. I still need to access at least one server which can’t support it yet. (And just one which doesn’t support it forces me to use the GPG approach so that it’s the same key everywhere.)
- the guide also tells you to use the new approach if it’s available to you :)
- GPG is still used for some other things, like signing git commits
Backing up the secret key material is still an issue with FIDO2.
You should add multiple keys to your logins and have a "backup" key which is separate one.
Especially when you lose physical key, you want to have different one and revoke lost one asap.
The same with private keys generated on a device - private key should stay on the device on which it was generated and never copied. If you need access from a different device you generate private key on another device and transfer public key only to be added to account.
Which in turn also makes physical keys that you can connect to different devices a bit more convenient as private key never leaves key and is not directly accessible by laptop that it is connected to.
Having a strong passphrase makes things a lot simpler. A classic convenience vs security tradeoff...
I can't use it to log in to my routers and other SSH gear, and don't expect to for the lifetime of the hardware.
With OpenSSH U2F it'll be decades before you won't ALSO need a more traditional key. That or use passwords (brrr)