From 4532bd01d57ee13c3ca881eceac1bf9da96a4d7e Mon Sep 17 00:00:00 2001 From: "djm@openbsd.org" Date: Mon, 30 Dec 2019 09:19:52 +0000 Subject: upstream: basic support for generating FIDO2 resident keys "ssh-keygen -t ecdsa-sk|ed25519-sk -x resident" will generate a device-resident key. feedback and ok markus@ OpenBSD-Commit-ID: 8e1b3c56a4b11d85047bd6c6c705b7eef4d58431 --- PROTOCOL.u2f | 2 ++ 1 file changed, 2 insertions(+) (limited to 'PROTOCOL.u2f') diff --git a/PROTOCOL.u2f b/PROTOCOL.u2f index 61b70d6ef..93601159c 100644 --- a/PROTOCOL.u2f +++ b/PROTOCOL.u2f @@ -235,6 +235,8 @@ The middleware library need only expose a handful of functions: /* Flags */ #define SSH_SK_USER_PRESENCE_REQD 0x01 + #define SSH_SK_USER_VERIFICATION_REQD 0x04 + #define SSH_SK_RESIDENT_KEY 0x20 /* Algs */ #define SSH_SK_ECDSA 0x00 -- cgit v1.2.3