Skip to content

Add support for Ed25519 keys - #156

Open
e-nomem wants to merge 1 commit into
FiloSottile:mainfrom
e-nomem:add-ed25519-keys
Open

e-nomem wants to merge 1 commit into
FiloSottile:mainfrom
e-nomem:add-ed25519-keys

Conversation

@e-nomem

@e-nomem e-nomem commented Dec 4, 2024 •

Copy link
Copy Markdown

This is basically the same as #26 but implements the automatic algo selection by checking the firmware version as you mentioned in the other PR.

Yubikeys officially added support for Ed25519 keys in firmware version 5.7.0. Upstream piv-go added support for it in go-piv/piv-go#157 (released in v2.2.0).

Note that Yubikey firmware 5.4.0 (technically 5.4.2 but I used the same version check as piv-go, see this comment) added support for AES management keys so I also used the same firmware version detection method to upgrade the management key to AES256.

Tested locally on macOS Sequoia with Yubikey firmware 5.7.1

@phiekl

phiekl commented Dec 17, 2024

Copy link
Copy Markdown

I tried this out using Debian 13 with a YubiKey 5.7.1. The setup configured an ed25519 key, which was exposed in the agent afterwards. Finally connecting to a server key worked without issues.

Using an older YubiKey 5.2.7 resulted in an ecdsa key instead, as expected. All good! 😀

@unhitched9271

Copy link
Copy Markdown

is this likely to be merged at some point?

@quite quite left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks pretty good. I have used go-piv for ed25519 on Yubikey in another project, and it was solid.

I'm not entirely convinced of switching to AES256 in the same commit.

Also, myself I have been doing semver comparisons using golang.org/x/mod/semver, which felt like a sensible dependency.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants