Comments (8)
It seems that the SSH package in Golang may support SK keys. I would like to test if it's possible when I have some time.
https://github.com/search?q=repo%3Agolang%2Fcrypto%20SKED25519&type=code
from omnisshagent.
Is there any news on this topic yet?
from omnisshagent.
I am currently investigating how to use the SK key. The following is the progress of the check and TODO.
- The golang crypto/ssh library defines the structure for the SK key, but it doesn't seem to have an interface ready to use the SK key.
- OpenSSH uses the libfido2 library. How to use it from go?
FIDO authenticator has several options.
TODO:
- Investigate how to use libfido2
- Investigate which FIDO authenticator options are necessary
from omnisshagent.
Basically I think the no-touch feature makes little sense with Yubikeys, then I can create a key and put it on an encrypted drive and only mount it when needed. The "more" security is then simply moot.
from omnisshagent.
You might be able to use ssh-sk-helper to your advantage.
https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html
Using FIDO2 Keys with Windows Subsystem for Linux (WSL) on Windows
In addition to a native SSH client, the Windows OpenSSH beta release also contains an SSH_SK_HELPER that can be used to bridge the hostβs FIDO2 support to WSL. All of this configuration must be done from inside the WSL environment, and relies on the Windows environment to be working correctly.
from omnisshagent.
https://www.reddit.com/r/yubikey/comments/11bot5f/minimum_requirements_for_notouchrequired_ssh/
It seems there are various challenges in using the no-touch-required option to enable key usage without touching. The YubiKey5 I have on hand doesn't work well with Openssh v9.2.2.0p1-Beta.
from omnisshagent.
Related Issues (20)
- Check and embed reference data from glyphs and other webviews
- Can't get WSL2 socket working HOT 10
- Support 1Password store HOT 1
- Named pipe stops working after a while the system is on HOT 31
- OmniSSHAgent.exe: Please state more precisely the installation and usage of the (WIN) binary HOT 5
- After a system Re-Boot I need to start OmniSSHAgent at least once to make it work again.
- Describe how to set up automatic startup in the README.md
- Keepassxc over pageant_shm integration doesn't seem to work HOT 7
- Populating duplicate tray entries HOT 5
- Notate the default socket file path in the configuration value
- gpg-agent support HOT 2
- Stopped working in windows 11 HOT 3
- No using asyncIO or Overlapped Results. HOT 3
- Prepare the socat pipe command for WSL2
- Corrected typos
- Prevention of duplicate launch
- Cannot retrieve comment information for private keys in OpenSSH format
- Benchmarking the performance of agent forwarding
- Automatic build with github actions HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
π Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. πππ
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google β€οΈ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from omnisshagent.