# Ssh with FIDO2 - how to set up? which PIN code?

**URL:** <https://onlykey.discourse.group/t/ssh-with-fido2-how-to-set-up-which-pin-code/749>\
**Category:** SSH, OpenPGP, GPG\
**Created:** [May 21, 2022, 2:00pm UTC](https://onlykey.discourse.group/t/ssh-with-fido2-how-to-set-up-which-pin-code/749 "2022-05-21T14:00:07Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Mango\_Mungo](https://yyz2.discourse-cdn.com/free1/user_avatar/onlykey.discourse.group/mango_mungo/32/26_2.png) [@Mango\_Mungo](https://onlykey.discourse.group/u/Mango_Mungo)\
**Post date:** [July 5, 2022, 11:10pm UTC](https://onlykey.discourse.group/t/ssh-with-fido2-how-to-set-up-which-pin-code/749/4 "2022-07-05T23:10:07Z")

</div>

A lot has become clear to me since this tip from Tim 😅

> [@Ssh-keygen on linux without the agent](https://onlykey.discourse.group/t/ssh-keygen-on-linux-without-the-agent/788/2):
>
> Using openssh with OnlyKey is a different thing then using the agent.

`ssh-keygen -t ecdsa-sk` & `ssh-keygen -t ed25519-sk` generated keys work great with OnlyKey for serverlogin.

Resident keys get stuck on invalid format:

```auto
marco@t520:~$ ssh-keygen -t ed25519-sk -O resident -f ~/.ssh/id_mykey_sk
Generating public/private ed25519-sk key pair.
You may need to touch your authenticator to authorize key generation.
Enter PIN for authenticator:
Key enrollment failed: invalid format

marco@t520:~$ ssh -V
OpenSSH_8.4p1 Debian-5, OpenSSL 1.1.1n 15 Mar 2022

```

Edit: Oh damn I got it 🙃  
Hints: onlykey-cli is only needed on one device.

```auto
onlykey-cli set-pin
ssh-keygen -t ed25519-sk -O resident -f ~/.ssh/id_ed25519_sk

```

After that, you can put the OnlyKey in all other devices and download all available resident keys & write public/private key files with _“ssh-keygen -K”_. Or add resident keys directly to ssh-agent without writing files to the file-system using _“ssh-add -K”._  
See OpenSSH 8.2 Release Notes: [FIDO2 resident keys](https://www.openssh.com/releasenotes.html#8.2)

```auto
marco@w530:~$ ssh-keygen -K
Enter PIN for authenticator:
You may need to touch your authenticator to authorize key download.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Saved ED25519-SK key to id_ed25519_sk_rk

```

😂 Incredible, an SSH key on a PIN-protected USB token. Works everywhere, no other tools needed except OpenSSH 8.2. SSH-key is also PIN+password protected.  
I will still test backup & restore on other OnlyKeys.

---

_[View the full topic](https://onlykey.discourse.group/t/ssh-with-fido2-how-to-set-up-which-pin-code/749)._
