https://www.yubico.com/store/2025/black-friday-sale/
Why doesn't my #yubikey work as #ssh key under #ArchLinux ?
- pcscd must be running
- ccid needs to be installed
- (maybe???) user needs to be part of pcscd
Joost van Dijk from @yubico tells us about #OpenSSH combined with the #FIDO standard at the @nluug #najaarsconferentie. This info applies on any FIDO #securitykey, not just #yubikey.
#opensourceconference #Linuxconference #conference #conferentie #NLUUG #nluug25nj #hardwarekey
FIDO2 USB Key, U2F USB Key, Cheap Yubico alternative, FIDO2, fido alliance certified security keys Replace your mobile authenticator with secure hardware OTP token! Easily programmed via NFC. Designed to use with Google, Facebook, Dropbox, GitHub, Wordpress, Office 365, Azure MFA etc.
This makes Yubikey a good backup proof way to use as passkeys, which is what I want.
Also using GPG as passkey doesn't have same non-resident/resident key limitation. Normally Yubikey can store only ~25 resident passkeys, which is annoying.
With GPG passkey you can store the resident data to a files, and use GPG in Yubikey for challenges only.
Some one in HN pointed out they use GPG for #Passkey authentication. I didn't get details how, but it probably is doable.
This would make GPG #Yubikey/Smartcard really great "One key to rule them all" solution.
1. You can login to SSH servers with GPG-agent and [A] key
2. You can encrypt with GPG
3. You can authenticate to web services via Passkeys with same [A]
I wonder how well ED25519 in A slot works for passkeys, when I have time I will try.
Yubikey users cannot access to X, because of a bad deploy:
I personally locked out of X because of this. Also the "recovery codes" section is also broken.
𝗪𝗲𝗿𝗲𝗹𝗱𝘄𝗶𝗷𝗱 𝗶𝗻𝗹𝗼𝗴𝗽𝗿𝗼𝗯𝗹𝗲𝗺𝗲𝗻 𝗯𝗶𝗷 𝗫, 𝗴𝗲𝗯𝗿𝘂𝗶𝗸𝗲𝗿𝘀 𝗴𝗲𝘃𝗿𝗮𝗮𝗴𝗱 '𝗬𝘂𝗯𝗶𝗸𝗲𝘆' 𝘁𝗲 𝗿𝗲𝗴𝗶𝘀𝘁𝗿𝗲𝗿𝗲𝗻
Gebruikers van socialemediaplatform X hebben wereldwijd last van een storing. Mensen die in willen loggen, krijgen de melding: 'Je moet je Yubikey opnieuw registreren'.