Markdown Edit

YubiKey OpenPGP and FIDO2 Security Key Workflow

This document summarizes troubleshooting findings regarding repeated PIN prompts, smartcard session resets, and FIDO2 vs OpenPGP key workflows when using a YubiKey on Linux (NixOS).

OpenPGP Smartcard PIN Prompt Behavior

When using a YubiKey for GnuPG (pass, GPG commit signing, or SSH via gpg-agent):

1. scdaemon and pcscd Conflicting Drivers

2. Card Timeout Invalidating PIN Cache

3. OpenPGP Card forcesig Setting

4. OpenPGP Touch Policy (UIF) Hardware Requirement

Hardware Support for SSH FIDO2 Security Keys

To achieve "Physical Touch per action, but PIN typed only once per session", standard SSH FIDO2 keys (ed25519-sk or ecdsa-sk) are preferred over OpenPGP SSH emulation.

Firmware Version Limitations

Configuration & Usage

  1. Generate an ecdsa-sk SSH key:
    ssh-keygen -t ecdsa-sk -C "yubikey-titan"
    
  2. Configure ~/.ssh/config to use the explicit identity:
    Host github.com
        IdentityFile ~/.ssh/id_ecdsa_sk
        IdentitiesOnly yes
    
  3. Register id_ecdsa_sk.pub on GitHub. Outgoing Git pushes will trigger a green touch prompt on the YubiKey without demanding GPG PIN re-entry.

References