Skip to content
Discussion options

You must be logged in to vote

Hi @ProfessorSalty,

Thanks for the kind words, I'm glad the tiny CA is working out for you!

  • For SSH CA support, you'll need the very latest version of step-ca, which supports using additional YubiKey PIV certificate slots 82-95 (called the "retired key management slots"). Otherwise you won't have enough certificate slots to have both X.509 and SSH CAs.

We don't have a tutorial for adding SSH support, but I can give you an overview of the steps you'll need to take:

  1. Stop your step-ca

  2. Generate SSH CA private keys on the YubiKey (probably into slots 82 and 83— but that depends on your setup. Be careful here because ykman appears to overwrite slots without asking). You'll need to use ykman

Replies: 2 comments 18 replies

Comment options

You must be logged in to vote
15 replies
@maraino
Comment options

@maraino
Comment options

@0x6c66
Comment options

@maraino
Comment options

@maraino
Comment options

Answer selected by tashian
Comment options

You must be logged in to vote
3 replies
@tashian
Comment options

@kaysond
Comment options

@kaysond
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
6 participants