awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
drduh avatar

drduh/YubiKey-Guide

0
View on GitHub↗
12,377 星标·1,247 分支·HTML·MIT·12 次浏览drduh.github.io/YubiKey-Guide↗

YubiKey Guide

This project is a comprehensive hardware security guide for using YubiKey tokens to manage encryption, digital signatures, and secure authentication. It provides technical instructions for configuring hardware security modules to handle digital identity and cryptographic materials.

The documentation focuses on the implementation of OpenPGP and SSH workflows, specifically covering the creation of master key hierarchies, the rotation of subkeys, and the use of hardware-backed keys for secure shell connections. It also details methods for verifying code authorship through signed Git commits and tags.

The guide covers broader security and access control areas, including device PIN management, physical user presence enforcement, and the creation of encrypted offline backups for identity recovery. It further explains the process of hardware key transfers and public key publication.

Features

  • Hardware Authentication - Using YubiKey hardware tokens to secure SSH connections and login sessions without storing private keys on a local disk.
  • Hardware Security Token Guides - Serves as a comprehensive manual for managing encryption and authentication via YubiKey hardware tokens.
  • Physical User Presence Attestations - Configures the hardware token to require a physical touch for every encryption, signature, or authentication operation.
  • Hardware Key Storage - Guides the transfer of private cryptographic material from local storage to a secure hardware element to prevent extraction.

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI
  • Secure Element PIN Controls - Sets up user and admin PINs on the security token to prevent unauthorized remote access to keys.
  • Git Commit Signature Verification - Provides a technical walkthrough for signing Git commits and tags using hardware-backed PGP keys to verify authorship.
  • GnuPG Key Management - Provides a comprehensive workflow for managing PGP key hierarchies and subkeys on a hardware security module.
  • Hierarchical Key Structures - Provides a workflow for creating a master key hierarchy and managing operational subkeys for enhanced security.
  • Hardware-Backed SSH Key Managers - Walks through the use of hardware-resident SSH keys to secure shell connections and manage agent forwarding.
  • Hardware Security Module Integrations - Provides technical instructions for configuring the internal settings and access requirements of hardware security modules.
  • Cryptographic Key Hierarchies - Guides the implementation of OpenPGP master key hierarchies and the rotation of operational subkeys.
  • Hardware-Backed Key Storage - Details how to store private cryptographic materials in a secure element to prevent extraction from the operating system.
  • Offline Secret Backups - Instructions for creating encrypted offline backups of secret keys to recover digital identities after hardware failure.
  • OpenPGP Key Lifecycles - Outlines the complete workflow for creating master keys, rotating subkeys, and maintaining recovery backups.
  • Smart Card Configuration - Instructs on modifying internal smart card settings to support OpenPGP keys on a security module.
  • Hardware Token Secret Recovery - Details the process of creating and using encrypted backups to restore identity after a hardware device is lost.
  • Security Key Factory Resets - Explains how to wipe hardware security keys to factory defaults and restore identity materials from encrypted backups.
  • Commit Signing - Enables the verification of code authorship by signing Git commits and tags with hardware-backed keys.
  • Cryptographic Signature Verification - Provides instructions for validating digital signatures against public keys to ensure the authenticity and integrity of messages.
  • Hardware Key Signing - Performs cryptographic signing operations on-device using hardware-backed keys to verify content authenticity.
  • PGP Email Encryptions - Integrates hardware security keys with email clients using PGP for end-to-end encrypted communication.
  • GnuPG Agent Forwarding - Explains how to securely forward a local GnuPG agent to remote hosts for signing and decryption tasks.
  • Hardware-Backed Data Encryption - Implements secure encryption and decryption of messages and files using hardware-backed private keys and user PINs.
  • Master Key Rotation - Covers the process of rotating root keys and extending the validity of subkeys to maintain security continuity.
  • Encrypted Secret Backups - Explains the creation of encrypted offline backups of secret keys for identity recovery after hardware loss.
  • Hardware Token PIN Management - Includes detailed guides for configuring and updating user and admin PINs to protect hardware-stored cryptographic materials.
  • User Presence Attestation - Provides configuration steps to enforce physical touch requirements for every encryption, signature, or authentication operation.
  • SSH Agent Forwarding - Provides instructions for configuring SSH agent forwarding to use hardware-backed keys on remote hosts.
  • Hardware and PKI Security - Comprehensive guide for using hardware keys for GPG, SSH, and authentication.
  • Star 历史

    drduh/yubikey-guide 的 Star 历史图表drduh/yubikey-guide 的 Star 历史图表

    常见问题解答

    drduh/yubikey-guide 是做什么的?

    This project is a comprehensive hardware security guide for using YubiKey tokens to manage encryption, digital signatures, and secure authentication. It provides technical instructions for configuring hardware security modules to handle digital identity and cryptographic materials.

    drduh/yubikey-guide 的主要功能有哪些?

    drduh/yubikey-guide 的主要功能包括:Hardware Authentication, Hardware Security Token Guides, Physical User Presence Attestations, Hardware Key Storage, Secure Element PIN Controls, Git Commit Signature Verification, GnuPG Key Management, Hierarchical Key Structures。

    drduh/yubikey-guide 有哪些开源替代品?

    drduh/yubikey-guide 的开源替代品包括: lfit/itpol — itpol is a framework for cryptographic key management, digital signature policies, and security hardening. It provides… maxgoedjen/secretive — Secretive is an SSH key manager that utilizes hardware-backed security modules to generate and store non-exportable… sekey/sekey — Sekey is a hardware-backed SSH key manager and authentication agent designed to isolate private keys from system… mystenlabs/sui — Sui is a blockchain platform featuring an object-centric state model and resource-oriented smart contracts. It… guanzhi/gmssl — GmSSL is an open-source cryptographic library that implements the Chinese national cryptographic standards SM2, SM3,… build-trust/ockam — Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an…

    YubiKey Guide 的开源替代方案

    相似的开源项目,按与 YubiKey Guide 的功能重合度排序。
    • lfit/itpollfit 的头像

      lfit/itpol

      4,891在 GitHub 上查看↗

      itpol is a framework for cryptographic key management, digital signature policies, and security hardening. It provides an IT policy template library and infrastructure access frameworks to establish organizational security guidelines and governance. The project focuses on cryptographic identity management through the use of PGP and SSH keys, alongside a security hardening guide for workstations. It defines standards for software supply chain security, specifically regarding the signing of code commits and software releases to ensure provenance. The system covers a broad range of security cap

      在 GitHub 上查看↗4,891
    • maxgoedjen/secretivemaxgoedjen 的头像

      maxgoedjen/secretive

      8,162在 GitHub 上查看↗

      Secretive is an SSH key manager that utilizes hardware-backed security modules to generate and store non-exportable private keys. It integrates with secure enclaves to ensure that sensitive cryptographic material remains within the hardware and cannot be exported from the device. The system implements a biometric authentication workflow, requiring fingerprint or wearable verification before a private key is released for signing operations. It also provides the ability to bridge signing requests to external hardware tokens for systems that lack a built-in secure enclave. The project includes

      Swiftmacsecure-enclavesecurity
      在 GitHub 上查看↗8,162
    • sekey/sekeysekey 的头像

      sekey/sekey

      2,514在 GitHub 上查看↗

      Sekey is a hardware-backed SSH key manager and authentication agent designed to isolate private keys from system memory. It utilizes a secure enclave to generate, store, and manage cryptographic key pairs, ensuring that sensitive material remains within a protected hardware environment and cannot be extracted by the host system. The project implements biometric-gated request signing, requiring a biometric authentication event before the hardware security module signs a cryptographic challenge. It functions as a middleware bridge that connects standard SSH protocols to these hardware-based sig

      Rust
      在 GitHub 上查看↗2,514
  • build-trust/ockambuild-trust 的头像

    build-trust/ockam

    4,628在 GitHub 上查看↗

    Ockam is a zero-trust networking framework designed to secure data transit between distributed applications using an identity-based network overlay. It provides the primitives necessary to establish mutually authenticated and end-to-end encrypted connections, removing the reliance on traditional network-layer security. The project is distinguished by its use of attribute-based access control and verifiable credentials to manage trust at scale. It implements cryptographic identity rotation to maintain identity continuity and integrates with hardware-backed key management systems to secure priv

    Rustauthenticationauthorizationcredentials
    在 GitHub 上查看↗4,628
  • 查看 YubiKey Guide 的所有 30 个替代方案→