Re: Resident SK keys lose verify-required on download
Jan Schermer <[email protected]> Sat, 25 Jul 2026 20:50:28 +0200
| Newsgroups | gmane.network.openssh.devel |
|---|---|
| Message-ID | <[email protected]> |
Isn't this enforced by the Yubikey when used for signing? If not, then this looks like a Yubikey vulnerability or incorrect generation in the first place. Or is it just cosmetic? Jan > On 25. 7. 2026, at 20:40, Savely Krasovsky via openssh-unix-dev <[email protected]> wrote: > > Hi, > > Resident credentials created with verify-required may lose the > SSH_SK_USER_VERIFICATION_REQD flag when downloaded using ssh-keygen -K > or ssh-add -K from authenticators with built-in UV. > > The credential retains FIDO_CRED_PROT_UV_REQUIRED, but the downloaded > OpenSSH key gets flags 0x21 instead of 0x25. > > I have opened a small patch with hardware validation here: > > https://github.com/openssh/openssh-portable/pull/701 > > I used Token2 Bio3 to verify, but this also an issue on YubiKey Bio, > but I don't have it on hands rn. > > Thanks, > Savely Krasovsky > _______________________________________________ > openssh-unix-dev mailing list > [email protected] > https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev