Situation has come up, requiring me to use a ssh private key file, as a second factor of authentication (primary is regular pw)
Honestly I would have prefered another method of second factor, but its not supported.
So to logon to the system,both a pw and a ssh private key is needed. My concern is that the client device gets compromised. A keylogger will get the password and the private file, can easily be copied.
I was thinking about putting the keyfile on a usb disk. This way I would access the keyfile for short periods of time only.
Alternatives could be smartcards, but I have absolutely no idea, if that is even possible or better.
Would love some ideas or feedback.
[link] [comments]
SOCIAL SHARE CARD GENERATOR