Skip to content

SSH Certificates and Yubikey #529

Answered by tashian
ProfessorSalty asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @ProfessorSalty,

Thanks for the kind words, I'm glad the tiny CA is working out for you!

  • For SSH CA support, you'll need the very latest version of step-ca, which supports using additional YubiKey PIV certificate slots 82-95 (called the "retired key management slots"). Otherwise you won't have enough certificate slots to have both X.509 and SSH CAs.

We don't have a tutorial for adding SSH support, but I can give you an overview of the steps you'll need to take:

  1. Stop your step-ca

  2. Generate SSH CA private keys on the YubiKey (probably into slots 82 and 83— but that depends on your setup. Be careful here because ykman appears to overwrite slots without asking). You'll need to use ykman

Replies: 1 comment 15 replies

Comment options

You must be logged in to vote
15 replies
@maraino
Comment options

@maraino
Comment options

@0x6c66
Comment options

@maraino
Comment options

@maraino
Comment options

Answer selected by tashian
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
5 participants