# The following was performed on Debian Stretch # Adapted from: # https://ubuntuforums.org/showthread.php?t=1557180&p=9743605 # http://blog.fkraiem.org/2013/03/13/linux-smart-card-authentication-openssh/ # # ===================================================================== # Option #1: Use public/private keys on card # # Note: A Public/Private Key on the card is required. See: # https://pastebin.com/D0geT5Ne # ===================================================================== # # Output public key as SSH key $ pkcs15-tool --read-ssh-key 707db33cfbd0712e0d5cfc4238fa85be44da990d Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCju5VBvBBjqR/v580MztBh5paDcaEIyd7GnAUnvKQ7N95VNs2JqyQIseubHDYipOuLSO15uOi5DEoA5gtzMym3ecjwrKNiRMwwHsdxiUhZwEVZZZd2zY5B/6oaWQ5rgiBioUbdwLEvRYS2Koe7xF7ggn+bKIyL4vUCTX681VyG7bt96f1YwNpAkH7O4pwi3AgagDHVtmVLgDCca1vQ5FV2e/Q/gRhNtqmONRX+wcdabHfdoKu+gKGBkxgR3icMlx/sF6zh+Ov//RtY0f+6R+2SUE5uIUjq/fvIfLI8l+dexB5KjEAerxvx+YH+HWKQMCDFmK7FLNOv1iA3LfDKzRJl Public Key # --------------------------------------------------------------------- # Jump to "Login to Server" section. # --------------------------------------------------------------------- # ===================================================================== # Option #2: Import existing SSH public/private keys # ===================================================================== # # Import Private SSH key # --------------------------------------------------------------------- $ pkcs15-init --store-private-key id_rsa --auth-id 01 --label 'SSH Key' Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 Security officer PIN [Security Officer PIN] required. Please enter Security officer PIN [Security Officer PIN]: User PIN [John Doe] required. Please enter User PIN [John Doe]: # Display all private keys # Note: SSH key has a different ID # --------------------------------------------------------------------- $ pkcs15-tool --list-keys Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 Private RSA Key [Certificate] Object Flags : [0x3], private, modifiable Usage : [0x4], sign Access Flags : [0x1D], sensitive, alwaysSensitive, neverExtract, local ModLength : 2048 Key ref : 0 (0x0) Native : yes Path : 3f0050150100 Auth ID : 01 ID : 707db33cfbd0712e0d5cfc4238fa85be44da990d MD:guid : 503f9232-5ab5-d056-3e60-c7e8fe7090d9 Private RSA Key [SSH Key] Object Flags : [0x3], private, modifiable Usage : [0x4], sign Access Flags : [0xD], sensitive, alwaysSensitive, neverExtract ModLength : 2048 Key ref : 1 (0x1) Native : yes Path : 3f0050150101 Auth ID : 01 ID : 02a446cce890490859cb7a2b5f9d17e7f1e1b430 MD:guid : 130f962e-81ff-6056-fc52-498b521dd064 # Output SSH Public Key # --------------------------------------------------------------------- $ pkcs15-tool --read-ssh-key 02a446cce890490859cb7a2b5f9d17e7f1e1b430 Using reader with a card: Broadcom Corp 5880 [Contacted SmartCard] (0123456789ABCD) 00 00 ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA40TJocjroR4UAjWiMJ9GahgRlVUZYG8f9Szuok6WHZPtK4qwuou0/ofCzV5W2BPBb/syQiGOxb9oI1rMCbL78VL2O6LDvrkzoN9ulk9euaY6mPN73VUrgcNTVOrHb7UbNcVC877NO4Mr9aoPTSMHZJVDcQXPxY6+PxaMYIqw5TcN90OAFYRsM8BSuqUMWQLqECyT3E2KQRAFRvBx3lDgQ50MnI57f4k7z4agEtjSdpTqFY+0kS1McP0lWt3tiqGoflk1cAtwu1Zr+j3ydIVq1l5v/qOTwgJ62VhVXKX1RajP74QyuJEG6RT1/7l2bLMsw8d1+kRZZrGAxpvyZ2xhAw== SSH Key # ===================================================================== # Login to Server # ===================================================================== # # Copy key to server # # Note: SSH key is from "ssh-rsa ... Key" # --------------------------------------------------------------------- # # Store key in ~/.ssh/authorized_keys # Login to server using PKCS11 # --------------------------------------------------------------------- $ ssh -I /usr/lib/x86_64-linux-gnu/pkcs11/opensc-pkcs11.so -l jdoe server.name Enter PIN for 'OpenSC Card (John Doe)': jdoe@server.name ~ $ # Create or edit ~/.ssh/config and add the following line: # --------------------------------------------------------------------- PKCS11Provider /usr/lib/x86_64-linux-gnu/pkcs11/opensc-pkcs11.so
Comments
0 B
|👍
/👎