{"repo":"drduh/YubiKey-Guide","free":true,"listed":false,"github":"https://github.com/drduh/YubiKey-Guide","clone":"git clone https://github.com/drduh/YubiKey-Guide.git","description":"Community guide to using YubiKey for GnuPG and SSH - protect secrets with hardware crypto.","language":"HTML","stars":12444,"topics":["yubikey","gpg","gnupg","ssh","security","gpg-agent","gpg-configuration","smartcard","remote-access","rsa-cryptography"],"license":"MIT","category":"security-tools","readme_excerpt":"This guide demonstrates how to store credentials on a YubiKey. The private keys cannot be copied back out of the device; a separate offline \"Certify\" key is retained only to replace or renew them. - Purchase YubiKey - Prepare setup environment - Download and verify Debian - Create bootable USB device - Prepare hardware - Install software - Prepare GnuPG - Configuration - Identity - Key algorithm - Expiration - Passphrase - Create Certify key - Create Subkeys - Verify keys - Backup keys - Export public key - Configure YubiKey - Change PIN - Set attributes - Transfer Subkeys - Signature key - Encryption key - Authentication key - Verify transfer - Finish setup - Using YubiKey - Encryption - Signature - Configure touch - SSH - Replace agents - Copy public key - Import SSH keys - SSH agent forwarding - Use ssh-agent - Use S.gpg-agent.ssh - Chained forwarding - GitHub - GnuPG agent forwarding - Legacy distributions - Chained GnuPG agent forwarding - Using multiple YubiKeys - Email - Thunderbird - Mailvelope - Mutt - Keyserver - Updating keys - Renew Subkeys - Rotate Subkeys - Reset YubiKey - Optional hardening - Improving entropy - Enable KDF - Network considerations - Notes - Troubleshooting - Alternative solutions - Additional resources --- Purchase YubiKey Choose a YubiKey model that includes the OpenPGP application. YubiKey Security Key and YubiKey Bio models do not include OpenPGP support and cannot be used with this guide. Verify the YubiKey at yubico.com/genuine. Select Ver","default_branch":null,"files":null,"tree":[],"storefront":"/r/drduh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/drduh/YubiKey-Guide/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}