Skip to content
This repository has been archived by the owner on Dec 31, 2024. It is now read-only.

keys/ma27: rotate once again #179

Merged
merged 1 commit into from
Jan 2, 2024
Merged

Conversation

Ma27
Copy link
Member

@Ma27 Ma27 commented Dec 24, 2023

It turns out that when using PIV rather than OpenPGP for SSH (yubikey-agent in this case), you cannot change the touch policy for enrolled keys[1].

However, it turns out that the default (always - touching the key for each SSH auth) is pretty annoying when running remote builds or making SSH signatures, so I had no choice but to rotate the keys once again.

It's not urgent at all to get this key deployed, I'm only filing this patch now to check every box on my "SSH rotation checklist" so I don't forget about it. Happy holidays 🎉

Finally, sorry for the additional noise!

[1] https://docs.yubico.com/yesdk/users-manual/application-piv/pin-touch-policies.html#touch-policies

It turns out that when using PIV rather than OpenPGP for SSH
(`yubikey-agent` in this case), you cannot change the touch policy for
enrolled keys[1].

However, it turns out that the default (`always` - touching the key for
each SSH auth) is pretty annoying when running remote builds or making
SSH signatures, so I had no choice but to rotate the keys once again.

It's not urgent at all to get this key deployed, I'm only filing this
patch now to check every box on my "SSH rotation checklist" so I don't
forget about it. Happy holidays 🎉

Finally, sorry for the additional noise!

[1] https://docs.yubico.com/yesdk/users-manual/application-piv/pin-touch-policies.html#touch-policies
@cole-h cole-h merged commit 2fd50d6 into NixOS:master Jan 2, 2024
@Ma27 Ma27 deleted the rotate-ma27-keys-again branch January 2, 2024 16:29
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants