[{"data":1,"prerenderedAt":311},["ShallowReactive",2],{"$f31q9wl1l1sxbb":3},{"title":4,"date":5,"tags":6,"categories":9,"draft":12,"_id":13,"slug":14,"path":15,"document":16,"excerpt":309,"readingTimeMinutes":310},"Configuring a YubiKey for use with OpenSSH","2024-06-09T00:00:00.000Z",[7,8],"unix","configurations",[10,11],"tooling","tips",false,"content:blog:ssh-ed25519-sk-yubikey","ssh-ed25519-sk-yubikey","\u002Fblog\u002Fssh-ed25519-sk-yubikey",{"frontmatter":17,"meta":18,"nodes":19},{},{},[20,34,38,46,50,58,88,91,127,134,153,156,235,243,298],[21,22,23,28,29,33],"p",{},[24,25,27],"a",{"href":26},"https:\u002F\u002Fwww.yubico.com\u002F","YubiKey's"," are a convenient way to introduce a physical form of two factor authentication into ones workflow. They support a variety of protocols, but in this guide we will walk through how to configure a YubiKey for use with OpenSSH via the \"new\" ",[30,31,32],"code",{},"ed25519-sk"," key type that supports FIDO compliant hardware keys.",[35,36,37],null,{},"more",[21,39,40,41,45],{},"In ",[24,42,44],{"href":43},"https:\u002F\u002Fwww.openssh.com\u002Ftxt\u002Frelease-8.2","release 8.2 of OpenSSH"," support for FIDO devices was added with public key types \"ecdsa-sk\" and \"ed25519-sk\" (-sk standing for \"security key\"). This key type is supported by YubiKey's with firmware version 5.2.3 or higher.",[47,48,49],"blockquote",{},"This release adds support for FIDO\u002FU2F hardware authenticators to OpenSSH. U2F\u002FFIDO are open standards for inexpensive two-factor authentication hardware that are widely used for website authentication.  In OpenSSH FIDO devices are supported by new public key types \"ecdsa-sk\" and \"ed25519-sk\", along with corresponding certificate types.",[21,51,52,53,57],{},"Let's get started by installing the latest version of OpenSSH via ",[24,54,56],{"href":55},"https:\u002F\u002Fbrew.sh\u002F","Homebrew",", along with the YubiKey Manager (ykman) CLI. The version of OpenSSH included with macOS is not compatible.",[59,60,63],"pre",{"language":61,"class":62},"sh","shiki shiki-themes tokyo-night dark:tokyo-night",[30,64,66],{"class":65},"language-sh",[67,68,71,75,79,82,85],"span",{"class":69,"style":70},"line","display: inline",[67,72,74],{"style":73},"color:#C0CAF5","$",[67,76,78],{"style":77},"color:#9ECE6A"," brew",[67,80,81],{"style":77}," install",[67,83,84],{"style":77}," openssh",[67,86,87],{"style":77}," ykman",[21,89,90],{},"Then, let's confirm that our YubiKey has a firmware that is greater than 5.2.3:",[59,92,93],{"language":61,"class":62},[30,94,95,104,105],{"class":65},[67,96,97,99,101],{"class":69,"style":70},[67,98,74],{"style":73},[67,100,87],{"style":77},[67,102,103],{"style":77}," list","\n",[67,106,107,110,113,117,121,124],{"class":69,"style":70},[67,108,109],{"style":73},"YubiKey",[67,111,112],{"style":77}," 5Ci",[67,114,116],{"style":115},"color:#A9B1D6"," (5.4.3) ",[67,118,120],{"style":119},"color:#89DDFF","[",[67,122,123],{"style":115},"OTP+FIDO+CCID",[67,125,126],{"style":119},"]",[21,128,129,130,133],{},"Next, we'll go ahead and enable a pin on our device via the ",[30,131,132],{},"change-pin"," command, as this a requirement for our use.",[59,135,136],{"language":61,"class":62},[30,137,138],{"class":65},[67,139,140,142,144,147,150],{"class":69,"style":70},[67,141,74],{"style":73},[67,143,87],{"style":77},[67,145,146],{"style":77}," fido",[67,148,149],{"style":77}," access",[67,151,152],{"style":77}," change-pin",[21,154,155],{},"And last, we'll generate the key on our device!",[59,157,158],{"language":61,"class":62},[30,159,160,104,180,104,196,104,229],{"class":65},[67,161,162,164,167,171,174,177],{"class":69,"style":70},[67,163,74],{"style":73},[67,165,166],{"style":77}," ssh-keygen",[67,168,170],{"style":169},"color:#E0AF68"," -t",[67,172,173],{"style":77}," ed25519-sk",[67,175,176],{"style":169}," -O",[67,178,179],{"style":77}," resident",[67,181,182,185,188,190,193],{"class":69,"style":70},[67,183,184],{"style":73},"Generating",[67,186,187],{"style":77}," public\u002Fprivate",[67,189,173],{"style":77},[67,191,192],{"style":77}," key",[67,194,195],{"style":77}," pair.",[67,197,198,201,204,207,210,213,216,219,221,224,226],{"class":69,"style":70},[67,199,200],{"style":73},"You",[67,202,203],{"style":77}," may",[67,205,206],{"style":77}," need",[67,208,209],{"style":77}," to",[67,211,212],{"style":77}," touch",[67,214,215],{"style":77}," your",[67,217,218],{"style":77}," authenticator",[67,220,209],{"style":77},[67,222,223],{"style":77}," authorize",[67,225,192],{"style":77},[67,227,228],{"style":77}," generation.",[67,230,231],{"class":69,"style":70},[67,232,234],{"style":233},"color:#0DB9D7","...",[21,236,237,238,242],{},"We specify ",[239,240,241],"em",{},"resident"," to indicate that the key handle is to be stored on the YubiKey itself, since we will be using this device with multiple computers.",[59,244,246],{"language":245,"class":62},"txt",[30,247,249,104,253,104,258,104,263,104,268,104,273,104,278,104,283,104,288,104,293],{"class":248},"language-txt",[67,250,251],{"class":69,"style":70},[67,252,241],{},[67,254,255],{"class":69,"style":70},[67,256,257],{},"        Indicate that the key handle should be stored on the FIDO",[67,259,260],{"class":69,"style":70},[67,261,262],{},"        authenticator itself.  This makes it easier to use the",[67,264,265],{"class":69,"style":70},[67,266,267],{},"        authenticator on multiple computers.  Resident keys may be",[67,269,270],{"class":69,"style":70},[67,271,272],{},"        supported on FIDO2 authenticators and typically require that a PIN",[67,274,275],{"class":69,"style":70},[67,276,277],{},"        be set on the authenticator prior to generation.  Resident keys",[67,279,280],{"class":69,"style":70},[67,281,282],{},"        may be loaded off the authenticator using ssh-add(1).  Storing",[67,284,285],{"class":69,"style":70},[67,286,287],{},"        both parts of a key on a FIDO authenticator increases the",[67,289,290],{"class":69,"style":70},[67,291,292],{},"        likelihood of an attacker being able to use a stolen authenticator",[67,294,295],{"class":69,"style":70},[67,296,297],{},"        device.",[21,299,300,301,304,305,308],{},"And that's all it takes -- simple enough. Now, when interacting with ",[239,302,303],{},"ssh"," or ",[239,306,307],{},"git"," you will be prompted to touch the YubiKey to bring that little bit of physical 2FA.","YubiKey's are a convenient way to introduce a physical form of two factor authentication into ones workflow. They support a variety of protocols, but in this guide we will walk through how to configure a YubiKey for use with OpenSSH via the \"new\" ed25519sk key type that supports FIDO compliant hardware keys.",2,1790648870581]