TheDragon 🔥<p><span class="h-card" translate="no"><a href="https://mastodon.social/@jpmens" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jpmens</span></a></span> ❤️ GPG agent forwarding with a Yubikey!</p><p>I've been using this method for a while now to control sudo authentication on my local machine, and all remote devices/VMs too. Allows me to leave an undesirably long/complex password for the user account in a password manager (as an escape hatch, but which I don't actually use).</p><p>With verification of presence via touch, and also the PIN on the Yubikey cached for only a short period of time, and it self destructing after 3 incorrect PIN entries... </p><p>End result is I have super convenient *and* secure local/remote two factor authentication and privelidge escalation. </p><p>I'm also using sudo-rs, which is a much more "minimal" implementation - just as I don't need the vast array of extra stuff that bundled into the traditional version.</p><p>I use <a href="https://hachyderm.io/tags/NixOS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NixOS</span></a> almost entirely, so only have need for Ansible in a few places... </p><p>That said, finding a way to utilize this for Ansible Vault has been on my to-do list for a while, so looks like you've solved that one for me! </p><p>Thank you 🙏</p>