Bug 3178 - When authenticating with a -sk key via agent, no 'touch security key' prompt displayed
Summary: When authenticating with a -sk key via agent, no 'touch security key' prompt ...
Status: CLOSED WORKSFORME
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: ssh (show other bugs)
Version: 8.2p1
Hardware: amd64 Linux
: P5 minor
Assignee: Assigned to nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-06-08 06:11 AEST by Kane
Modified: 2021-03-04 09:53 AEDT (History)
1 user (show)

See Also:


Attachments
Annotated log of ssh -v demonstrating the issue (3.51 KB, text/plain)
2020-06-08 06:11 AEST, Kane
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Kane 2020-06-08 06:11:50 AEST
Created attachment 3408 [details]
Annotated log of ssh -v demonstrating the issue

When using a security key login that requires touch, no message is printed by the client or server while waiting for the touch. On security keys that support it, the light begins flashing, but this may be hard to notice.

Excerpt from the attached session log:

debug1: Offering public key: /home/kane/.ssh/id_ecdsa_sk ECDSA-SK SHA256:1bjhZUm1GLemKIhbwX33nP4zpLuW3VBPdH9kN1LH0bU explicit authenticator agent
debug1: Server accepts key: /home/kane/.ssh/id_ecdsa_sk ECDSA-SK SHA256:1bjhZUm1GLemKIhbwX33nP4zpLuW3VBPdH9kN1LH0bU explicit authenticator agent
[[ Exchange hangs until sk touch ]]
Authenticated with partial success.

Some component - either the ssh client binary, or the agent - should print a message along the lines of "Please touch your security key." immediately before requesting a signature from a touch-required security key. It may be awkward for the agent to determine the correct terminal to print to, so I suggest the client relying on the touch-required flag.

Issue found on Ubuntu 20.04.0
Comment 1 Kane 2020-06-08 06:33:14 AEST
This only occurs when the -sk key is added to the agent. Using `SSH_AUTH_SOCK= ssh ...`, a prompt is displayed like normal.

Workaround: Block ssh-add from adding -sk keys by default.
Comment 2 Damien Miller 2020-06-26 13:57:27 AEST
ssh-agent is able to notify via SSH_ASKPASS. Do you have that configured?
Comment 3 Damien Miller 2020-08-28 13:17:28 AEST
Closing; this works for me. If you are able to reproduce this with an agent configured to use ssh-askpass, then please reopen.
Comment 4 Damien Miller 2021-03-04 09:53:58 AEDT
close bugs that were resolved in OpenSSH 8.5 release cycle