Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How to protect GitLab-connected SSH key with Yubikey

Blog post from GitLab

Post Details
Company
Date Published
Author
Brendan O'Leary
Word Count
842
Company Posts That Month
22
Language
English
Hacker News Points
-
Post removed?
No
Summary

Two-factor authentication (2FA) significantly enhances account security, but its effectiveness varies with the method used, with SMS being less secure due to vulnerability to SIM-swapping attacks. GitLab 14.8 introduces the ability to use 2FA hardware to protect SSH keys by supporting ecdsa-sk and ed25519-sk key types, which require a FIDO/U2F device for user authentication. This method combines something you know (such as a password) with something you have (a physical device) to verify identity, increasing security. Updating to OpenSSH 8.8 on macOS was necessary for the author to generate these keys, involving adjustments to the system path. Once generated, the keys were added to GitLab, requiring physical confirmation via a YubiKey for every interaction, thus ensuring that even if the SSH key were compromised, unauthorized access would still be prevented by the need for physical device presence.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.