2001-09-18 09:06:21 +04:00
|
|
|
How to use smartcards with OpenSSH?
|
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
OpenSSH contains experimental support for authentication using Cyberflex
|
|
|
|
smartcards and TODOS card readers, in addition to the cards with PKCS#15
|
|
|
|
structure supported by OpenSC.
|
2001-09-25 04:21:28 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
WARNING: Smartcard support is still in development.
|
|
|
|
Keyfile formats, etc are still subject to change.
|
2001-09-25 04:21:28 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
To enable sectok support:
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
(1) install sectok:
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
Sources and instructions are available from
|
2001-09-18 09:44:34 +04:00
|
|
|
http://www.citi.umich.edu/projects/smartcard/sectok.html
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
(2) enable sectok support in OpenSSH:
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-05 20:11:45 +04:00
|
|
|
$ ./configure --with-sectok[=/path/to/libsectok] [options]
|
2001-09-18 09:44:34 +04:00
|
|
|
|
2001-09-18 09:06:21 +04:00
|
|
|
(3) load the Java Cardlet to the Cyberflex card:
|
|
|
|
|
|
|
|
$ sectok
|
|
|
|
sectok> login -d
|
|
|
|
sectok> jload /usr/libdata/ssh/Ssh.bin
|
|
|
|
sectok> quit
|
|
|
|
|
|
|
|
(4) load a RSA key to the card:
|
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
Please don't use your production RSA keys, since
|
2001-09-18 09:06:21 +04:00
|
|
|
with the current version of sectok/ssh-keygen
|
2002-04-23 16:48:46 +04:00
|
|
|
the private key file is still readable.
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
$ ssh-keygen -f /path/to/rsakey -U <readernum, eg. 0>
|
2001-09-18 09:06:21 +04:00
|
|
|
|
|
|
|
In spite of the name, this does not generate a key.
|
|
|
|
It just loads an already existing key on to the card.
|
|
|
|
|
|
|
|
(5) optional:
|
|
|
|
|
|
|
|
Change the card password so that only you can
|
|
|
|
read the private key:
|
|
|
|
|
|
|
|
$ sectok
|
|
|
|
sectok> login -d
|
|
|
|
sectok> setpass
|
|
|
|
sectok> quit
|
|
|
|
|
|
|
|
This prevents reading the key but not use of the
|
|
|
|
key by the card applet.
|
|
|
|
|
|
|
|
Do not forget the passphrase. There is no way to
|
|
|
|
recover if you do.
|
|
|
|
|
|
|
|
IMPORTANT WARNING: If you attempt to login with the
|
|
|
|
wrong passphrase three times in a row, you will
|
|
|
|
destroy your card.
|
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
To enable OpenSC support:
|
|
|
|
|
|
|
|
(1) install OpenSC:
|
|
|
|
|
|
|
|
Sources and instructions are available from
|
|
|
|
http://www.opensc.org/
|
|
|
|
|
|
|
|
(2) enable OpenSC support in OpenSSH:
|
|
|
|
|
|
|
|
$ ./configure --with-opensc[=/path/to/opensc] [options]
|
|
|
|
|
|
|
|
(3) load a RSA key to the card:
|
|
|
|
|
|
|
|
Not supported yet.
|
|
|
|
|
|
|
|
Common smartcard options:
|
|
|
|
|
|
|
|
(1) tell the ssh client to use the card reader:
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
$ ssh -I <readernum, eg. 0> otherhost
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
(2) or tell the agent (don't forget to restart) to use the smartcard:
|
2001-09-18 09:06:21 +04:00
|
|
|
|
2002-04-23 16:48:46 +04:00
|
|
|
$ ssh-add -s <readernum, eg. 0>
|
2001-09-18 09:06:21 +04:00
|
|
|
|
|
|
|
-markus,
|
2002-04-23 16:48:46 +04:00
|
|
|
Sat Apr 13 13:48:10 EEST 2002
|