No SSH public key authentication using smartcard and jumphost (Linux) #20936

Closed
opened 2026-01-31 07:28:19 +00:00 by claunia · 5 comments
Owner

Originally created by @cmonty14 on GitHub (Dec 1, 2023).

Windows Terminal version

1.18.2822.0

Windows build number

11.0.22621.2715

Other Software

Gpg4win 4.2.0

Steps to reproduce

I connect a Nitrokey security-token (that is comparable to Yubikey) with OpenPGP keys to my client.
And I want to use this Nitrokey for SSH login to remote servers.

For this I installed GPG4Win on my client and configured file gpg-agent.conf:

enable-ssh-support
To Enable support for PuTTY
enable-putty-support
To Enable support for the native Microsoft OpenSSH binaries (requires gpg 2.4.0 / Gpg4win 4.1.0 or higher)
enable-win32-openssh-support
use-standard-socket
default-cache-ttl 600
max-cache-ttl 7200

Then I (re-) start the gpg-agent and try to SSH into the Jumphost using command ssh (in Windows PowerShell profile).
Here I get a popup window where I must enter the PIN previously set on Nitrokey.
After this I'm connected to the jumphost shell (Linux).

Now I want to connect to the target server using command ssh .

I think this fails because SSH agent forwarding is not working.

Expected Behavior

Public key authentication for SSH connection to any target server from jumphost.

Actual Behavior

I need to enter (user) password requested by target server.

Originally created by @cmonty14 on GitHub (Dec 1, 2023). ### Windows Terminal version 1.18.2822.0 ### Windows build number 11.0.22621.2715 ### Other Software Gpg4win 4.2.0 ### Steps to reproduce I connect a Nitrokey security-token (that is comparable to Yubikey) with OpenPGP keys to my client. And I want to use this Nitrokey for SSH login to remote servers. For this I installed GPG4Win on my client and configured file gpg-agent.conf: ``` enable-ssh-support To Enable support for PuTTY enable-putty-support To Enable support for the native Microsoft OpenSSH binaries (requires gpg 2.4.0 / Gpg4win 4.1.0 or higher) enable-win32-openssh-support use-standard-socket default-cache-ttl 600 max-cache-ttl 7200 ``` Then I (re-) start the gpg-agent and try to SSH into the Jumphost using command ssh <fqdn-jumphost> (in Windows PowerShell profile). Here I get a popup window where I must enter the PIN previously set on Nitrokey. After this I'm connected to the jumphost shell (Linux). Now I want to connect to the target server using command ssh <fqdn-server>. I think this fails because SSH agent forwarding is not working. ### Expected Behavior Public key authentication for SSH connection to any target server from jumphost. ### Actual Behavior I need to enter (user) password requested by target server.
claunia added the Needs-TriageIssue-BugResolution-External labels 2026-01-31 07:28:19 +00:00
Author
Owner

@floh96 commented on GitHub (Dec 1, 2023):

Agent forwarding is not supported, please follow https://github.com/PowerShell/Win32-OpenSSH/issues/1461 for updates

@floh96 commented on GitHub (Dec 1, 2023): Agent forwarding is not supported, please follow https://github.com/PowerShell/Win32-OpenSSH/issues/1461 for updates
Author
Owner

@lhecker commented on GitHub (Dec 1, 2023):

Thank you @floh96! I would've had trouble finding that issue. 🙂
/dup https://github.com/PowerShell/Win32-OpenSSH/issues/1461

@lhecker commented on GitHub (Dec 1, 2023): Thank you @floh96! I would've had trouble finding that issue. 🙂 /dup https://github.com/PowerShell/Win32-OpenSSH/issues/1461
Author
Owner

@microsoft-github-policy-service[bot] commented on GitHub (Dec 1, 2023):

Hi! We've identified this issue as a duplicate of one that exists on somebody else's Issue Tracker. Please make sure you subscribe to the referenced external issue for future updates. Thanks for your report!

@microsoft-github-policy-service[bot] commented on GitHub (Dec 1, 2023): Hi! We've identified this issue as a duplicate of one that exists on somebody else's Issue Tracker. Please make sure you subscribe to the referenced external issue for future updates. Thanks for your report! <!-- Policy app identification https://img.shields.io/static/v1?label=PullRequestIssueManagement. -->
Author
Owner

@cmonty14 commented on GitHub (Dec 1, 2023):

Actually I don't want to jump to a Windows host.
I need "Authentication forwarding" on a Windows client where SSH connection is initiated.

@cmonty14 commented on GitHub (Dec 1, 2023): Actually I don't want to jump to a Windows host. I need "Authentication forwarding" on a Windows client where SSH connection is initiated.
Author
Owner

@lhecker commented on GitHub (Dec 4, 2023):

@cmonty14 I didn't say this specifically, but you need to report issues with terminal applications to the application maintainers. We only maintain the terminal itself, which is basically akin to a browser. Basically, our only purpose is launching applications and then showing their output visually. Or in other words, if we're a browser, then your issue with ssh is akin to an issue with a website.

I was fairly certain that https://github.com/PowerShell/Win32-OpenSSH/issues/1461 would be the right fit, but you make a good point regarding the OS installed on the forwarding host. These smartcard related issues don't inspire me with confidence either though: https://github.com/PowerShell/Win32-OpenSSH/issues?q=is%3Aissue+is%3Aopen+smartcard

In any case, if you believe none of the existing issues there are a good fit for your problem, please report the issue at https://github.com/PowerShell/Win32-OpenSSH/issues anyways, as none of us are familiar with OpenSSH internals and only the OpenSSH maintainers can help you further if anything.

@lhecker commented on GitHub (Dec 4, 2023): @cmonty14 I didn't say this specifically, but you need to report issues with terminal applications to the application maintainers. We only maintain the terminal itself, which is basically akin to a browser. Basically, our only purpose is launching applications and then showing their output visually. Or in other words, if we're a browser, then your issue with ssh is akin to an issue with a website. I was fairly certain that https://github.com/PowerShell/Win32-OpenSSH/issues/1461 would be the right fit, but you make a good point regarding the OS installed on the forwarding host. These smartcard related issues don't inspire me with confidence either though: https://github.com/PowerShell/Win32-OpenSSH/issues?q=is%3Aissue+is%3Aopen+smartcard In any case, if you believe none of the existing issues there are a good fit for your problem, please report the issue at https://github.com/PowerShell/Win32-OpenSSH/issues anyways, as none of us are familiar with OpenSSH internals and only the OpenSSH maintainers can help you further if anything.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#20936