Resident SK keys lose verify-required on download
Jan Schermer
jan at schermer.cz
Sun Jul 26 04:50:28 AEST 2026
Isn't this enforced by the Yubikey when used for signing? If not, then this looks like a Yubikey vulnerability or incorrect generation in the first place. Or is it just cosmetic?
Jan
> On 25. 7. 2026, at 20:40, Savely Krasovsky via openssh-unix-dev <openssh-unix-dev at mindrot.org> wrote:
>
> Hi,
>
> Resident credentials created with verify-required may lose the
> SSH_SK_USER_VERIFICATION_REQD flag when downloaded using ssh-keygen -K
> or ssh-add -K from authenticators with built-in UV.
>
> The credential retains FIDO_CRED_PROT_UV_REQUIRED, but the downloaded
> OpenSSH key gets flags 0x21 instead of 0x25.
>
> I have opened a small patch with hardware validation here:
>
> https://github.com/openssh/openssh-portable/pull/701
>
> I used Token2 Bio3 to verify, but this also an issue on YubiKey Bio,
> but I don't have it on hands rn.
>
> Thanks,
> Savely Krasovsky
> _______________________________________________
> openssh-unix-dev mailing list
> openssh-unix-dev at mindrot.org
> https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev
More information about the openssh-unix-dev
mailing list