PuTTY

Compatible Nitrokeys

3A/C/Mini

Passkey

HSM 2

Pro 2

FIDO2

Storage 2

Start

U2F

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

Este mini-howto asume que la Nitrokey ha sido inicializada y contiene claves criptográficas.

Requerido en el lado del cliente:

1) Concurso

Start pageant.exe. That this is running is shown in the notification area of the taskbar.

img1

Un doble clic abre la vista de las teclas actuales.

img2

Después de insertar la llave se ve así.

img3

Si no se muestra nada aquí, es posible que pageant tenga que reiniciarse o que otra aplicación ya esté utilizando el stick. ¡Un posible agente pgp en ejecución debe ser terminado! Ahora sólo necesitamos la clave pública que queremos almacenar en la configuración ssh del servidor. Por lo tanto presionamos CTRL mientras insertamos el stick…

img4

and then view the Pageant-PublicKeys.txt.

img5

I searched for the ssh-rsa entry of the auth key and added the line on the server to the authorized_keys.

2) PuTTY

Hay sorprendentemente poco que decir sobre PuTTY en sí mismo.

img6

«Intentar la autenticación mediante Pageant» debe estar configurado, que es el valor por defecto de todos modos.

That’s it, as soon as you connect to the server while pageant is running and you have the keys, you will be asked for the password of the Crypto-Stick and can log in.

3) openpgp-minidriver (opcional)

Si te molesta que Windows informe cada vez que conectas el stick que no se ha podido encontrar ningún controlador para la «Smartcard», puedes librarte de ello. Sólo tienes que instalar la versión x86 o x64 del controlador mencionado y la tarjeta inteligente se ve así:

img7