GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Chris Wiegman (chris@mastodon.chriswiegman.com)'s status on Wednesday, 13-Sep-2023 23:43:37 JST Chris Wiegman Chris Wiegman

    After years of using my Yubikey and my GPG key for SSH/GIT I’m thinking of switching that to using 1Password’s newer features for the same. Anyone doing that? Thoughts on the approach?

    In conversation Wednesday, 13-Sep-2023 23:43:37 JST from mastodon.chriswiegman.com permalink
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 13-Sep-2023 23:43:35 JST feld feld
      in reply to
      If 1Password is offering the ability to do this for ssh it would be via U2F which not all sshd support yet. Only the latest OS releases are likely to allow you to login with it.

      That's why Yubikey GPG is superior -- it is just a normal RSA or ED25519 ssh key (for a Yubikey 5)
      In conversation Wednesday, 13-Sep-2023 23:43:35 JST permalink
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 13-Sep-2023 23:45:01 JST feld feld
      in reply to
      • feld
      If you're still running MacOS install Secretive which will give you another ssh agent with your key stored in the Secure Enclave. It's nice having the equivalent of a built-in Yubikey into my laptop for when I'm not carrying my Yubikey.

      https://github.com/maxgoedjen/secretive
      In conversation Wednesday, 13-Sep-2023 23:45:01 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: repository-images.githubusercontent.com
        GitHub - maxgoedjen/secretive: Store SSH keys in the Secure Enclave
        Store SSH keys in the Secure Enclave. Contribute to maxgoedjen/secretive development by creating an account on GitHub.
    • Embed this notice
      feld (feld@bikeshed.party)'s status on Wednesday, 13-Sep-2023 23:46:43 JST feld feld
      in reply to
      • feld
      ahh, it looks like they went an even worse route: just a weird ssh-agent they provide that uses normal SSH keys that are held in 1Password. Which means the private key can be extracted.

      https://developer.1password.com/docs/ssh/agent/
      In conversation Wednesday, 13-Sep-2023 23:46:43 JST permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: developer.1password.com
        1Password SSH agent | 1Password Developer
        Use the 1Password SSH agent to authenticate SSH and Git clients without your private key ever leaving 1Password.
    • Embed this notice
      Chris Wiegman (chris@mastodon.chriswiegman.com)'s status on Wednesday, 13-Sep-2023 23:48:35 JST Chris Wiegman Chris Wiegman
      in reply to
      • feld

      @feld Thanks. In this case 1Password actually has a built-in SSH agent for all this now (using either RSA or ED25519 keys). In setting up it seems like it should handle all of what I need to connect to but I’ll look a little deeper at some of this first.

      In conversation Wednesday, 13-Sep-2023 23:48:35 JST permalink
      feld likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.