https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht...
https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.ht...
I may end up using a mix of this and a GPG integration once I learn more about how that works with SSH. I still need to dig into PIV/PAM/Keychain/FileVault/etc...
Thanks for the top though :)
I may be misunderstanding but I use U2F with OpenSSH (8.3). The private key is not on the local machine. It's still SSH public/private key pair but the private key on the computer is only a "key handle", not the real private key. The private key is protected on the security key. I don't mind copying that private key around: although it looks like a private key, it's just a key handle and not the actual private key.
Still, I'm trying to avoid leaving so many breadcrumbs on my systems if they aren't needed.