!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

648 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues164 Servers

Load older messages


SenderMessageTime
4 Dec 2023
@lily:lily.flowersLily Foster * ssh-sk-helper in the darwin openssh package from nixpkgs has /nix/store/czcpqds7n8211xjbb1v6sdh8qizpmq6g-libfido2-1.13.0/lib/libfido2.1.dylib as LC_LOAD_DYLIB on the mach-o 15:17:27
@kranzes:matrix.orgIlan Joselevich (Kranzes)couldn't find libsk-libfido215:17:31
@lily:lily.flowersLily Fosterbut what even is that. our openssh on linux doesn't have that either, so is it something darwin specific??15:17:54
@kranzes:matrix.orgIlan Joselevich (Kranzes)https://github.com/Yubico/libfido2/pull/6515:18:14
@lily:lily.flowersLily Fostereither way, our openssh is built with the flag that is supposed to enable that support and the helper is successfully built. so i really don't see why it wouldn't work with it15:18:18
@kranzes:matrix.orgIlan Joselevich (Kranzes)idk what to do anymore 😭15:19:26
@kranzes:matrix.orgIlan Joselevich (Kranzes)so many different issues saying different things15:19:37
@lily:lily.flowersLily Fosterthat was removed in https://github.com/Yubico/libfido2/commit/2ba6c6afe5f2d1717bf366da043ccb515fbed8de15:19:48
@lily:lily.flowersLily Fosterso ssh-sk-helper is the equivalent to that lib now15:20:08
@lily:lily.flowersLily Fosterand is what we build15:20:10
@lily:lily.flowersLily Fosterwe just don't have a way currently to use nixpkgs openssh's sshd instead of macOS's15:20:28
@kranzes:matrix.orgIlan Joselevich (Kranzes)can we just use SK_PROVIDER thing for now?15:21:41
@kranzes:matrix.orgIlan Joselevich (Kranzes)to test it out15:21:43
@lily:lily.flowersLily Fosterwhat, with apple's openssh?15:21:54
@kranzes:matrix.orgIlan Joselevich (Kranzes)yeah15:22:07
@kranzes:matrix.orgIlan Joselevich (Kranzes)I don't think I can't do that from my Linux system15:24:32
@kranzes:matrix.orgIlan Joselevich (Kranzes)and not even sure if it works on Ventura15:24:43
@lily:lily.flowersLily Foster that might work? it looks like you can set SSH_SK_PROVIDER in the env even if it was not compiled with support and have it dlopen the provider 15:27:05
@kranzes:matrix.orgIlan Joselevich (Kranzes)
In reply to @lily:lily.flowers
lily@darwin03> sw_vers
ProductName:		macOS
ProductVersion:		13.6.1
BuildVersion:		22G313
someone says it's fixed in macOS 13.2 RC (22D49)
15:27:05
@lily:lily.flowersLily Fosterif it's a recent enough openssh version15:27:14
@kranzes:matrix.orgIlan Joselevich (Kranzes)
In reply to @kranzes:matrix.org
someone says it's fixed in macOS 13.2 RC (22D49)
clearly not then, because we're on 13.6
15:27:26
@lily:lily.flowersLily Fosteridk if dlopen'ing the nixpkgs provider might work, but i support we could try it15:27:31
@kranzes:matrix.orgIlan Joselevich (Kranzes)Is there anything I can do to help with this from a Linux system?15:27:54
@lily:lily.flowersLily Foster not sure. it looks like sk-usbhid.c is the file that would need to be built as a standalone shared lib (with ENABLE_SK_INTERNAL defined and SK_STANDALONE defined), but the openssh build system doesn't seem to support that? 15:38:25
@kranzes:matrix.orgIlan Joselevich (Kranzes)Maybe I should just generate a key just for this?15:47:12
@kranzes:matrix.orgIlan Joselevich (Kranzes)Im wondering if some tpm2 protected key will work 15:47:34
@kranzes:matrix.orgIlan Joselevich (Kranzes)Does MacOS support pkcs11 ssh stuff?15:48:39
@lily:lily.flowersLily Fosterprobably?15:48:59
@kranzes:matrix.orgIlan Joselevich (Kranzes)Honestly at this point I don't assume MacOS supports anything15:55:35
5 Dec 2023
@federicodschonborn:matrix.org@federicodschonborn:matrix.org changed their profile picture.00:38:09

Show newer messages


Back to Room ListRoom Version: 6