Yubico with new 4096-bit keys and gpg-agent for ssh authentication
31–40 of 51 posts
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#32Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course.
Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#33Offtopic question: Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course. Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#34Nitrokey[1] is about the same price as Yubico but has open source firmware & hardware . You might also know them as CryptoStick[2]. [1] https://www.nitrokey.com/ [2] https://blog.mozilla.org/security/2013/02/13/using-cryptosti...
Edit: Also, does this have gpg-agent / ssh support?
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#35Looked at these last year but opted for smartcard and secure pinpad reader instead.
Can you provide links to what you chose instead?
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#36Offtopic question: Is there any FDE software that supports keeping decryption keys on a network server? You would still need to enter user authentication to obtain the decryption key of course. Use case: We are a HIPAA environment, I want a hard drive to be useless if it is removed from the building.
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#37Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#38Earlier quoted context omitted.
Can you provide links to what you chose instead?
I dunno about him, but I do something similar on one of my machines. I use an SCM SPR-532 USB reader with pinpad and an OpenPGP v2 smart card. More info and pictures here - https://grepular.com/Smart_Cards_and_SSH_Authentication
I've been thinking about it, but it's a bit confusing figuring out what cards are compatible and donating to the foundation is nice but a bit expensive.
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#39Are the github keys they sold cheaply compatible with 4096 bit keys? I'm loathe to buy another, considering i've got 3 already...
Re: Yubico with new 4096-bit keys and gpg-agent for ssh authentication
#40Nitrokey[1] is about the same price as Yubico but has open source firmware & hardware . You might also know them as CryptoStick[2]. [1] https://www.nitrokey.com/ [2] https://blog.mozilla.org/security/2013/02/13/using-cryptosti...
This looks really neat. Anyone also use these? Thoughts? I might get myself one. Edit: Also, does this have gpg-agent / ssh support?
But, yes, it does work with gpg-agent with ssh support.