pkg.sopackage field notes

brew / rang 4996

Installer yubikey-agent avec Homebrew

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de yubikey-agent pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install yubikey-agent

provider-native install command

aperçu

Résumé du paquet

Seamless ssh-agent for YubiKeys and other PIV tokens

Commandes et alias

  • yubikey-agent

historique

Historique du projet et usages

yubikey-agent is Filippo Valsorda’s Go ssh-agent for YubiKeys and other PIV tokens, packaged because it makes hardware-backed SSH keys feel like a normal SSH_AUTH_SOCK workflow.

Historique du projet

The project appeared publicly in 2020, in the same period when OpenSSH 8.2 introduced native FIDO/U2F security-key support. yubikey-agent chose a different compatibility path: use the YubiKey PIV applet to present ordinary SSH public keys through an agent interface, so existing servers did not need support for the newer `-sk` SSH key types.

The README emphasizes three design goals that shaped its history: one-command setup, resilience across unplugging and sleep, and keys generated on the YubiKey so private material cannot be extracted. It is written in Go and built on go-piv/piv-go plus Go’s SSH libraries.

Its documentation also candidly records the tradeoffs: keeping a persistent PIV transaction helps PIN caching and UX, but can conflict with gpg-agent, YubiKey Manager, and other tools that want the same PIV applet.

Historique d'adoption

Early adoption came from security-conscious developers who wanted hardware-backed SSH without the fragility of gpg-agent, manual PKCS#11 loading, or server-side FIDO2 support. A Hacker News launch discussion in May 2020 framed it as a friendly way to plug in a key and SSH securely with minimal setup.

Packaging spread through Homebrew, AUR/Arch-style packaging, NixOS modules, FreeBSD ports, Alpine testing, Debian, and Ubuntu. The README’s install instructions are package-manager first, which helped the tool become a normal service rather than a custom local build.

Modes d'utilisation

Users install the package, start the service, run `yubikey-agent -setup` to generate a key on the YubiKey, and point `SSH_AUTH_SOCK` or per-host `IdentityAgent` settings at the agent socket. After that, SSH sees an ordinary agent while the YubiKey enforces PIN and touch policy.

The tool is commonly compared with OpenSSH FIDO2 keys, gpg-agent with the OpenPGP applet, raw ssh-agent PKCS#11 loading, pivy-agent, and macOS Secure Enclave tools such as Secretive. Its niche is the compatibility and UX middle ground: hardware-backed keys with ordinary SSH public-key compatibility.

Pourquoi les passionnés de paquets s'y intéressent

yubikey-agent is a package-nerd favorite because it collapses a historically fiddly stack into one daemon and one socket. It is not the only hardware-backed SSH route, but it is one of the cleanest examples of wrapping smart-card behavior in a familiar Unix interface.

It also tells a packaging story about defaults: Homebrew services, systemd user units, NixOS services, pcscd, and SSH_AUTH_SOCK all matter as much as the binary itself.

Chronologie

  • 2020-02: OpenSSH 8.2 introduces built-in FIDO/U2F security-key SSH support, setting the context for hardware-backed SSH alternatives.
  • 2020-04: Early yubikey-agent issue traffic discusses PIV applet locking behavior with YubiKey Manager.
  • 2020-05-10: yubikey-agent is discussed on Hacker News as an easy Go ssh-agent for YubiKeys.
  • 2020-06: Go module metadata shows early v0.1.x releases such as v0.1.2 and v0.1.3.
  • 2020s: The package lands across Homebrew, NixOS/nixpkgs, FreeBSD ports, Arch/AUR, Debian/Ubuntu, and Alpine testing.

Related projects

  • Related projects include go-piv/piv-go, yubico-piv-tool, YKCS11, OpenSSH, gpg-agent, OpenSC, pivy-agent, Secretive, SeKey, YubiKey Manager, and OpenSSH FIDO2 security-key support.

posture de sécurité

Niveau de risque : orange

broad file, network, media, or database tool signal. formula declares a Homebrew service.

Classificateur de risque

risque orange · confiance moyen · infrastructure

Pourquoi

  • broad file, network, media, or database tool signal
  • formula declares a Homebrew service

Signaux

  • metadata:service
  • text:ssh

Comportement d'installation

  • Aucune métadonnée de bottle Homebrew n’a été enregistrée.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

exécutables

Exécutables installés

CommandeTypeExpositionNote
yubikey-agentexécutableexécutable indexéDécouvert depuis l'index local des exécutables.

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-08-03
version du gestionnaire0.1.6
gestionnaire mis à jour2026-07-25
données localesinconnu
amontnon disponible
dernière version détectéenon détecté
  • OKAucun avertissement de fraîcheur n'a été généré.

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:yubikey-agent
Version0.1.6
Gestionnaire de paquetsHomebrew
Page d'accueilhttps://github.com/FiloSottile/yubikey-agent
Dépôthttps://github.com/FiloSottile/yubikey-agent
Dernière mise à jour2026-07-25T21:32:50+02:00
Pulseupdated
Bouteillenon enregistré
Serviceaucun déclaré

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • curated package history
  • pkgdb category and tag curation