allan icon

SmartCards - OpenSSH

allan | PRO | 07/18/17 07:42:06 PM UTC | 0 ⭐ | 446 👁️ | Never ⏰ | []
Bash |

4.39 KB

|

None

|

0 👍

/

0 👎

# The following was performed on Debian Stretch
# Adapted from:
#    https://ubuntuforums.org/showthread.php?t=1557180&p=9743605
#    http://blog.fkraiem.org/2013/03/13/linux-smart-card-authentication-openssh/
#
# =====================================================================
# Option #1: Use public/private keys on card
#
# Note: A Public/Private Key on the card is required. See:
#    https://pastebin.com/D0geT5Ne
# =====================================================================
#
# Output public key as SSH key
$ pkcs15-tool --read-ssh-key 707db33cfbd0712e0d5cfc4238fa85be44da990d
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCju5VBvBBjqR/v580MztBh5paDcaEIyd7GnAUnvKQ7N95VNs2JqyQIseubHDYipOuLSO15uOi5DEoA5gtzMym3ecjwrKNiRMwwHsdxiUhZwEVZZZd2zY5B/6oaWQ5rgiBioUbdwLEvRYS2Koe7xF7ggn+bKIyL4vUCTX681VyG7bt96f1YwNpAkH7O4pwi3AgagDHVtmVLgDCca1vQ5FV2e/Q/gRhNtqmONRX+wcdabHfdoKu+gKGBkxgR3icMlx/sF6zh+Ov//RtY0f+6R+2SUE5uIUjq/fvIfLI8l+dexB5KjEAerxvx+YH+HWKQMCDFmK7FLNOv1iA3LfDKzRJl Public Key
 
# ---------------------------------------------------------------------
# Jump to "Login to Server" section.
# ---------------------------------------------------------------------
 
# =====================================================================
# Option #2: Import existing SSH public/private keys
# =====================================================================
#
# Import Private SSH key
# ---------------------------------------------------------------------
$ pkcs15-init --store-private-key id_rsa --auth-id 01 --label 'SSH Key'
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
Security officer PIN [Security Officer PIN] required.
Please enter Security officer PIN [Security Officer PIN]: 
User PIN [John Doe] required.
Please enter User PIN [John Doe]: 
 
# Display all private keys
# Note: SSH key has a different ID
# ---------------------------------------------------------------------
$ pkcs15-tool --list-keys
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
Private RSA Key [Certificate]
    Object Flags   : [0x3], private, modifiable
    Usage          : [0x4], sign
    Access Flags   : [0x1D], sensitive, alwaysSensitive, neverExtract, local
    ModLength      : 2048
    Key ref        : 0 (0x0)
    Native         : yes
    Path           : 3f0050150100
    Auth ID        : 01
    ID             : 707db33cfbd0712e0d5cfc4238fa85be44da990d
    MD:guid        : 503f9232-5ab5-d056-3e60-c7e8fe7090d9
 
Private RSA Key [SSH Key]
    Object Flags   : [0x3], private, modifiable
    Usage          : [0x4], sign
    Access Flags   : [0xD], sensitive, alwaysSensitive, neverExtract
    ModLength      : 2048
    Key ref        : 1 (0x1)
    Native         : yes
    Path           : 3f0050150101
    Auth ID        : 01
    ID             : 02a446cce890490859cb7a2b5f9d17e7f1e1b430
    MD:guid        : 130f962e-81ff-6056-fc52-498b521dd064
 
# Output SSH Public Key
# ---------------------------------------------------------------------
$ pkcs15-tool --read-ssh-key 02a446cce890490859cb7a2b5f9d17e7f1e1b430
Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00
ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA40TJocjroR4UAjWiMJ9GahgRlVUZYG8f9Szuok6WHZPtK4qwuou0/ofCzV5W2BPBb/syQiGOxb9oI1rMCbL78VL2O6LDvrkzoN9ulk9euaY6mPN73VUrgcNTVOrHb7UbNcVC877NO4Mr9aoPTSMHZJVDcQXPxY6+PxaMYIqw5TcN90OAFYRsM8BSuqUMWQLqECyT3E2KQRAFRvBx3lDgQ50MnI57f4k7z4agEtjSdpTqFY+0kS1McP0lWt3tiqGoflk1cAtwu1Zr+j3ydIVq1l5v/qOTwgJ62VhVXKX1RajP74QyuJEG6RT1/7l2bLMsw8d1+kRZZrGAxpvyZ2xhAw== SSH Key
 
# =====================================================================
# Login to Server
# =====================================================================
#
# Copy key to server
#
# Note: SSH key is from "ssh-rsa ... Key"
# ---------------------------------------------------------------------
#
# Store key in ~/.ssh/authorized_keys
 
# Login to server using PKCS11
# ---------------------------------------------------------------------
$ ssh -I /usr/lib/x86_64-linux-gnu/pkcs11/opensc-pkcs11.so -l jdoe server.name
Enter PIN for 'OpenSC Card (John Doe)': 
jdoe@server.name ~ $
 
# Create or edit ~/.ssh/config and add the following line:
# ---------------------------------------------------------------------
PKCS11Provider /usr/lib/x86_64-linux-gnu/pkcs11/opensc-pkcs11.so

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎