PuTTY

Compatible Nitrokeys

3A/C/Mini

Passkey

HSM 2

Pro 2

FIDO2

Storage 2

Start

U2F

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

To mini-howto zakłada, że Nitrokey został zainicjalizowany i zawiera klucze kryptograficzne.

Wymagania po stronie klienta:

1) Strona

Start pageant.exe. That this is running is shown in the notification area of the taskbar.

img1

Podwójne kliknięcie otwiera widok bieżących klawiszy.

img2

Po włożeniu klucza wygląda to następująco.

img3

Jeśli nic się tu nie wyświetla, być może trzeba zrestartować pageant lub inna aplikacja korzysta już z drążka. Ewentualnie działający pgp-agent musi zostać zlikwidowany! Teraz potrzebujemy tylko klucz publiczny, który chcemy zapisać w konfiguracji ssh serwera. Dlatego wciskamy CTRL podczas wkładania pendrive’a…

img4

and then view the Pageant-PublicKeys.txt.

img5

I searched for the ssh-rsa entry of the auth key and added the line on the server to the authorized_keys.

2) PuTTY

O samym PuTTY jest zaskakująco mało do powiedzenia.

img6

„Attempt authentication using Pageant” musi być ustawione, co i tak jest domyślne.

That’s it, as soon as you connect to the server while pageant is running and you have the keys, you will be asked for the password of the Crypto-Stick and can log in.

3) openpgp-minidriver (opcjonalnie).

Jeśli denerwuje Cię, że Windows po każdym podłączeniu pendrive’a zgłasza, że nie znaleziono sterownika dla „Smartcard”, możesz się tego pozbyć. Wystarczy zainstalować wersję x86 lub x64 wyżej wymienionego sterownika i smartcard wygląda tak:

img7