PuTTY

Compatible Nitrokeys

3A/C/Mini

Passkey

HSM 2

Pro 2

FIDO2

Storage 2

Start

U2F

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

✓

active

✓

active

⨯

inactive

Este mini-howto assume que a Nitrokey foi inicializada e contém chaves criptográficas.

Requerido do lado do cliente:

1) Concurso

Start pageant.exe. That this is running is shown in the notification area of the taskbar.

img1

Um duplo clique abre a visualização das teclas actuais.

img2

Depois de inserir a chave, fica assim.

img3

Se nada for exibido aqui, o concurso pode ter que ser reiniciado ou outra aplicação já está usando o bastão. Um possível agente pgp em execução deve ser terminado! Agora só precisamos da chave pública que queremos armazenar na configuração ssh do servidor. Por isso pressionamos CTRL enquanto inserimos o stick…

img4

and then view the Pageant-PublicKeys.txt.

img5

I searched for the ssh-rsa entry of the auth key and added the line on the server to the authorized_keys.

2) PuTTY

Há surpreendentemente pouco a dizer sobre a própria PuTTY.

img6

«Tentativa de autenticação usando o Pageant» deve ser definida, que é o padrão de qualquer forma.

That’s it, as soon as you connect to the server while pageant is running and you have the keys, you will be asked for the password of the Crypto-Stick and can log in.

3) openpgp-minidriver (opcional)

Se está aborrecido por o Windows reportar sempre que ligar o stick que não foi encontrado nenhum driver para o «Smartcard», pode ver-se livre dele. Você só tem que instalar a versão x86 ou x64 do driver acima mencionado e o smartcard tem este aspecto:

img7