Skip to content

Backup ed25519-sk generated by ssh-keygen #24

Closed Answered by polhenarejos
M11158002 asked this question in Q&A
Discussion options

You must be logged in to vote

This is not allowed by FIDO Alliance. The way to backup your keys is using a secondary FIDO device. Instead of having a replica of your keys in your secondary device, secondary device is also registered in all your services. Every time you add your primary device, you should also add your secondary device. Therefore, in case your primary device gets broken, you will be able to login using the secondary device, the backup. This also applies for ssh accounts.

In case you need really the backup of your ssh keys, Pico HSM would be a better choice. Pico HSM allows to export and import private/secret keys by using secure mechanisms (DKEK and XKEK). You can use Pico HSM with SSH as explained here:

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by M11158002
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants