SSH with Yubikey and signed OpenSSH certificate

SSH with Yubikey and signed OpenSSH certificate

avatar

Hello! We are trying to configure a SSH session to use a Yubikey for authentication. The Yubikey's PIV certificate acts as the private key and we created a signed OpenSSH certificate out of it. The SSH server trusts the signing CA.
This setup works great with either SecureCRT and the default openssh client. What's important about this concept is that you can define the Yubikey's PIV certificate as private key in the SSH session.
This doesn't seem to be possible in RDM, I can only define a file there. It's also not possible to configure the certificate in the certificate tab an leave the private key tab empty, RDM complains that no private key was specified.

Is the above scenario possible at all with RDM? Am I overlooking things maybe?

Best regards, Christian

All Comments (4)

avatar

Hello,

Thank you for reaching out regarding this matter.

I’ll need to run some tests on my end, as I haven’t found any indication that this should not work.
I’ll follow up with additional information as soon as I have more details.

Best regards,

Jacob Lafrenière

avatar

Hello,

Thank you for your patience.

I'm currently working with my internal team to determine whether this setup is supported in RDM and to see if we can replicate a similar configuration on our end.

To assist with the investigation, could you please provide the following details:

  • The version of RDM you are using
  • The type of data source you are using
  • Whether this setup has worked previously in RDM


This information will help us better understand the issue and move forward more effectively.

I look forward to your reply.

Best regards,

Jacob Lafrenière

avatar

Hi Jacob,

the version is 2025.2.20.0 64-bit (JIT). It has never worked as I am unable to set a certificate and leave the private key entry empty, as the private key is located on the Yubikey in this case.
What do you mean by "type of data source"? In which setting?

Christian

avatar

Hello,

Thank you for the follow-up.

After a bit of research, I found that this functionality was requested in the past, and our development team has already opened an internal case regarding it.

I recommend upvoting the following feature request to help us prioritize it:
https://forum.devolutions.net/topics/35700/add-an-ability-to-use-yubikey-pivpkcs-as-ssh-key

Your input will help revive the discussion and highlight user interest.

Best regards,

Jacob Lafrenière