Hacker News new | past | comments | ask | show | jobs | submit | redninja83's comments login

Sorry, but Yubico Security Keys support up to 25 resident keys (https://support.yubico.com/hc/en-us/articles/360013647720-Se...)


Its possible to do, and once set up its a reasonably smooth process.

- Init Your TPM

- Create a key+cert on your TPM using certutil.exe

- Grab your public key

- Use WinCryptSSH (https://github.com/buptczq/WinCryptSSHAgent) as your SSH agent and away you go

These are very simplified steps, but there are howtos floating around (eg https://blog.habets.se/2016/10/Windows-SSH-client-with-TPM.h...)


For anyone who has the same issue, Headscale [https://github.com/juanfont/headscale] may be an answer, that has simple OpenID integration now


Headscale isn't really anywhere near as useful until there's an ios client. Even one you have to compile yourself and use a developer key to load would be better than none at all.


Somewhat related: Why are the iOS, macOS and Windows GUI clients for Tailscale not open-source?


Nebula is great - super simple to set up and get started if you have a VM to use as a lighthouse. Lots of cloud providers free tiers are have enough resources to host a lighthouse as well.

Certificate management is its one weakness at the moment. There are a growing number of projects floating around attempting to solve that though:

- https://github.com/unreality/nebula-mesh-admin

- https://github.com/b177y/starship

- https://github.com/symkat/MeshMage

Plus im sure defined networks has their own solution in the works as well.


As other have suggested, Nebula (https://github.com/slackhq/nebula) is pretty elegant. It has groups-based access built in which is extremely convenient.

You can bolt-on SSO fairly easily - just create a certificate signing service. I created https://github.com/unreality/nebula-mesh-admin in a weekend, so its fairly easy to add a SSO flow in.


Thanks! This seems pretty interesting, I will definitely explore it further.


1000% this. We started using chargify before Stripe when there were very few options and they were cheap.

They increased pricing and added a bunch of features we dont use, plus our payment processor (DPS now Windcave) refuse to export our customer card data.

So for the past few years we are slowly migrating people away as they update their card details, but its been a frustrating experience.

Don't use Chargify or DPS/Windcave


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: