Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

u/subway answered the GPG portion in https://news.ycombinator.com/item?id=16480945

As for the PIV portion: Unfortunately, PIV will not work either. Right now, OpenSSH’s ssh-agent doesn’t have the ability to handle EDSA keys when using PKCS#11 (which is how the agent communicates with the “card”.

The enhancement request is at https://bugzilla.mindrot.org/show_bug.cgi?id=2474

Unfortunately, although people have been maintaining patches, there’s been no official action (that I know of) on this.



You might note that in the above directions, PKCS#11 is avoided anyway. They instead rely in using gpg-agent as an ssh agent.


True! For the article linked, PIV isn't used, and so my linked bug doesn't apply.

But, with regard's to the parent comments's "this or any guide" qualifier, then this can become an important point, and so I think it's worth noting.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: