Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Would it be possible to use an Age key that lives on a Yubikey via age-plugin-yubikey? #377

Open
solomon-b opened this issue Aug 9, 2023 · 10 comments

Comments

@solomon-b
Copy link

I know you can do this with GPG but it would be really awesome if I could use Age instead.

@Mic92
Copy link
Owner

Mic92 commented Aug 13, 2023

This is blocked on getsops/sops#1103

@nyabinary
Copy link

Bummer :<

@Mic92 Mic92 mentioned this issue Nov 2, 2023
@Mic92
Copy link
Owner

Mic92 commented Nov 2, 2023

Now we got: getsops/sops#1335 that unlocks tpm and yubikey plugins for age.

@solomon-b
Copy link
Author

Oh very cool. Will you need to do work on sops-nix or will it just work once its merged into sops?

@Mic92
Copy link
Owner

Mic92 commented Nov 3, 2023

It should just work (TM). Maybe we need some environment (PATH?) variable for sops-install-secrets so age plugins are discovered? But this shouldn't take long to implement.

@nyabinary
Copy link

It should just work (TM). Maybe we need some environment (PATH?) variable for sops-install-secrets so age plugins are discovered? But this shouldn't take long to implement.

Documentation and a guide would also be appreciated

@Kranzes
Copy link

Kranzes commented Nov 6, 2023

If you know a bit of Go and got a bit of sanity left in you, please help out with getsops/sops#1335. I didn't write any of the code there, it was @Mic92.

@mannp
Copy link

mannp commented Apr 2, 2024

I was keen to give this a try with the yubikey-support branch :) but wasn't sure if it was at a beta stage? :)

@Mic92
Copy link
Owner

Mic92 commented May 9, 2024

@mannp I will probably switch to use https://github.com/olastor/age-plugin-fido2-hmac instead, because than we can use other security keys beyond just yubikeys.

@mannp
Copy link

mannp commented May 9, 2024

@mannp I will probably switch to use https://github.com/olastor/age-plugin-fido2-hmac instead, because than we can use other security keys beyond just yubikeys.

Having choice over sec keys sounds like a good plan, and thanks for the update :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants