Questions tagged [yubikey]

21 questions
13
votes
1 answer

Using Yubikey for sudo over SSH session

I currently use Kryptonite to handle protecting the private key I use to SSH into hosts. This works well, except when I need to escalate to root. When I sudo I have to go copy a randomly generated 20-character string out of my password manager,…
thomasfedb
  • 415
  • 5
  • 14
13
votes
2 answers

SSH Two-Factor auth (2FA) with a yubikey

I have got this slick little yubikey and I want to add an additional layer of security when authenticating ssh sessions. On the server side I've already disabled password authentication and only permit the use of ssh keys when logging in. The…
ben lemasurier
  • 758
  • 6
  • 21
7
votes
1 answer

Is it possible to ignore a missing PAM module?

I am configuring yubico-pam to enable passwordless sudo access using challenge-response from a Yubikey. The following works: # /etc/pam.d/sudo auth sufficient pam_yubico.so mode=challenge-response auth required …
CodeGnome
  • 285
  • 2
  • 9
3
votes
1 answer

ssh PIV error "sign_and_send_pubkey: signing failed for RSA "Public key for Digital Signature": agent refused operation"

I had to recently rebuild my laptop. In the process, I switched from Fedora31 to Kubuntu 20.04 LTS. Everything in the switch went without a hitch, except for one thing. Where I work we use 2FA for all logins, and utilize a yubi key for this…
Egyas
  • 121
  • 1
  • 10
2
votes
1 answer

smart card for UAC only

I'm in the process of configuring USB Yubikeys as a smart card for our company so that staff can elevate to an admin account (added to the computer's local administrators group) by simply inserting the key and typing a PIN. If possible I would like…
captcha
  • 568
  • 5
  • 16
2
votes
0 answers

Freeradius multi-factor auth with LDAP and Yubikey

I just set up a freeradius server and would like to be able to authenticate using both the password of a ldap user and the yubico otp generated from their yubikey. It is working using the ldap password out of the box without any configuration, but I…
eli0T
  • 120
  • 11
2
votes
0 answers

Removing additional password field from ssh login on Ubuntu 20

I just bought a Yubikey a few days back. I have tried to use the key to login to SSL without a password. I have it working, but it displays an error and shows interactive auth prompts. The only real prompts are the customer and Yubikey one. How can…
1
vote
1 answer

"NO_PROPOSAL_CHOSEN" when trying to authenticate with a certificate from smartcard using swanctl

I'm trying to create a VPN tunnel between two VMs (named A and B) with strongSwan (for what matters, I use swanctl here) using a host-to-host configuration (as described here ) and a smartcard for B's authentication I generated CA certificate and I…
Nobozoa
  • 11
  • 5
1
vote
1 answer

Use ssh key on GPG card to decrypt data

When a Windows instance is created in AWS, its password is encrypted using the public part of an SSH key. It's then possible to use the following command to retrieve the encrypted password: aws ec2 get-password-data…
a-h
  • 111
  • 3
1
vote
1 answer

Smartcard Authentication on Windows Domain Controller using Yubikey for Windows Login

I have a Yubikey 5 NFC and I am trying to configure it on a test bench for windows login authentication. I cannot seem to get the certificate to enroll on the Yubikey. I have followed the Yubikey Smartcard deployment guide, but does not seem to be…
ubuntuuber
  • 113
  • 3
1
vote
1 answer

SSH agent: `sign_and_send_pubkey: signing failed for ECDSA-SK ... from agent: agent refused operation` except very first time

I have an ecdsa-sk keypair that I generated and added to my github account (tied to a yubikey). If I try any connection using that key, such as git push, I get: sign_and_send_pubkey: signing failed for ECDSA-SK "[...]/.ssh/id_ecdsa_sk" from agent:…
Allen
  • 111
  • 5
1
vote
0 answers

Cannot redirect Yubikey into VMWare Horizon VDI with Ubuntu OS

I am not able to redirect to Yubikey into the VMWare Horizon VDI. the guest OS is Ubuntu 20.04 I have install the vmware client & the required driver with the following command: sudo ./install_viewagent.sh -m yes -U yes -A yes sudo apt install…
user1172579
  • 111
  • 1
1
vote
0 answers

Securing SSH access with YubiKey: ed25519-sk vs. pam_yubico

I just got some YubiKeys to secure my important accounts and am now wondering about the best way of securing access to some VPS boxes I have. Up until now, I have disabled password-based login and used SSH keys to connect to the servers. As far as I…
1
vote
0 answers

Yubikey won't receive an imported SSH auth key

I had a SSH key which I imported without problems in my GPG keyring as auth key using pem2openpgp from monkeysphere. The imported key works fine. I removed its SSH version from ~/.ssh and switched from ssh-agent to gnupg-agent with SSH support. The…
Qippur
  • 135
  • 1
  • 10
0
votes
0 answers

Setting up OIDC with ADFS - Invalid UserInfo Request

Background So I've been pulling my hair out the past few weeks trying to get OIDC authentication working based on ADFS in various applications, specifically Proxmox VE as well as Gitea. The reason why I am doing this is primarily driven by Proxmox,…
1
2