Anyone gone down this path?
Anyone gone down this path?
The modern way is SSH resident keys. However, this requires a “modern” SSH version (8.2), but does not add a dependency on GPG. Modern in this case, is a version from 2020.
https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht...
I may end up using a mix of this and a GPG integration once I learn more about how that works with SSH. I still need to dig into PIV/PAM/Keychain/FileVault/etc...
Thanks for the top though :)
I may be misunderstanding but I use U2F with OpenSSH (8.3). The private key is not on the local machine. It's still SSH public/private key pair but the private key on the computer is only a "key handle", not the real private key. The private key is protected on the security key. I don't mind copying that private key around: although it looks like a private key, it's just a key handle and not the actual private key.
Still, I'm trying to avoid leaving so many breadcrumbs on my systems if they aren't needed.
But, I just copy my ~/.gnupg directory to my new machine or to some backup server and all my gpg backed ssh keys/configs are portable. It's not terribly hard.
But for the SSH key use case, none of this matters. Unless you need compatibility with old SSH servers/clients, resident keys are substantially simpler, because they cut out 1 tool entirely and don’t require copying any directories to other machines.
> But for the SSH key use case, none of this matters.
Agreed.
[0]: https://news.ycombinator.com/item?id=22324074
[1]: https://github.blog/2021-05-10-security-keys-supported-ssh-g...
To be clear, my goal is to simply plug in my SK to a fresh OS install and "magically" be able to SSH into my servers.
The process for using a discoverable key on a new machine re-imports the relevant public key and private key handle to the new machine when you “ssh-keygen -K”. Its roughly equivalent to copying key material around with a flash drive, but without the need to remember two physical items.
Not being able to extract SSH keys helps very little.