{"repo":"Foxboron/ssh-tpm-agent","free":true,"listed":false,"github":"https://github.com/Foxboron/ssh-tpm-agent","clone":"git clone https://github.com/Foxboron/ssh-tpm-agent.git","description":":computer: :key: ssh-agent for TPMs","language":"Go","stars":744,"topics":["go-tpm","golang","security","ssh","ssh-agent","tpm","tpm2"],"license":"MIT","category":"security-tools","readme_excerpt":"SSH agent for TPM ================= ssh-tpm-agent is a ssh-agent compatible agent that allows keys to be created by the Trusted Platform Module (TPM) for authentication towards ssh servers. TPM sealed keys are private keys created inside the Trusted Platform Module (TPM) and sealed in .tpm suffixed files. They are bound to the hardware they are produced on and can't be transferred to other machines. This allows you to utilize a native client instead of having to side load existing PKCS11 libraries into the ssh-agent and/or ssh client. The project uses TPM 2.0 Key Files implemented through the go-tpm-keyfiles project. Features A working ssh-agent . Create shielded ssh keys on the TPM. Creation of remotely wrapped SSH keys for import. PIN support, dictionary attack protection from the TPM allows you to use low entropy PINs instead of passphrases. TPM session encryption. Proxy support towards other ssh-agent servers for fallbacks. SWTPM support Instead of utilizing the TPM directly, you can use --swtpm or export SSH TPM AGENT SWTPM=1 to create an identity backed by swtpm which will be stored under /var/tmp/ssh-tpm-agent . Note that swtpm provides no security properties and should only be used for testing. Installation The simplest way of installing this plugin is by running the following: Alternatively download the pre-built binaries. Usage Note: For ssh-tpm-agent you can specify the TPM owner password using the command line flags -o or --owner-password , which are preferred. Al","default_branch":null,"files":null,"tree":[],"storefront":"/r/Foxboron","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Foxboron/ssh-tpm-agent/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}