Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: GnuPG: users

Question about authentication subkeys and SSH

 

 

GnuPG users RSS feed   Index | Next | Previous | View Threaded


jh at jameshoward

Jul 22, 2009, 12:59 PM

Post #1 of 3 (607 views)
Permalink
Question about authentication subkeys and SSH

I have created a 2048-bit RSA subkey that is authentication only. I'd
like to use this with SSH. A bit of Googling suggests this cannot be
used directly unless it is on a smart card, but it isn't clear. Have I
correctly interpreted this?

Thank you,
James

--
James P. Howard, II, MPA
jh [at] jameshoward
Attachments: signature.asc (0.16 KB)


dkg at fifthhorseman

Jul 22, 2009, 1:12 PM

Post #2 of 3 (555 views)
Permalink
Re: Question about authentication subkeys and SSH [In reply to]

On 07/22/2009 03:59 PM, James P. Howard, II wrote:
> I have created a 2048-bit RSA subkey that is authentication only. I'd
> like to use this with SSH. A bit of Googling suggests this cannot be
> used directly unless it is on a smart card, but it isn't clear. Have I
> correctly interpreted this?

You can use such a subkey without a smartcard by using software provided
by the monkeysphere project:

http://web.monkeysphere.info/

Assuming this is the only authentication-capable subkey on your only gpg
secret key, you'd simply do:

monkeysphere subkey-to-ssh-agent

which would load the key into the agent for use. You can pass
additional parameters to ssh-add at the end of the argument list. For
example, if you want to ensure that the key is only held by the agent
for an hour, do:

monkeysphere subkey-to-ssh-agent -t 3600

hope this helps,

--dkg (one of the monkeysphere developers)
Attachments: signature.asc (0.87 KB)


jh at jameshoward

Jul 22, 2009, 2:50 PM

Post #3 of 3 (550 views)
Permalink
Re: Question about authentication subkeys and SSH [In reply to]

On Wed Jul 22 2009 16:12:34 GMT-0400 (EDT) , Daniel Kahn Gillmor
<dkg [at] fifthhorseman> wrote:

> On 07/22/2009 03:59 PM, James P. Howard, II wrote:
>> I have created a 2048-bit RSA subkey that is authentication only.
>> I'd like to use this with SSH. A bit of Googling suggests this
>> cannot be used directly unless it is on a smart card, but it isn't
>> clear. Have I correctly interpreted this?
>
> You can use such a subkey without a smartcard by using software
> provided by the monkeysphere project:
>
> http://web.monkeysphere.info/
>
> Assuming this is the only authentication-capable subkey on your only
> gpg secret key, you'd simply do:
>
> monkeysphere subkey-to-ssh-agent
>
> which would load the key into the agent for use. You can pass
> additional parameters to ssh-add at the end of the argument list.
> For example, if you want to ensure that the key is only held by the
> agent for an hour, do:
>
> monkeysphere subkey-to-ssh-agent -t 3600

That looks like the missing link I was searching for!

Thank you.

--
James P. Howard, II, MPA
jh [at] jameshoward
Attachments: signature.asc (0.16 KB)

GnuPG users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.