Guides · RDP-FIDO-GATE

FIDO2 and SSH: the four approaches compared

“Use a YubiKey for SSH” can mean four different things. They differ in one question that matters more than it seems: does the SSH port still answer people who have no key?

Updated

1. SSH keys that live on a security key (ed25519-sk)

Since OpenSSH 8.2 a key pair can be bound to a FIDO authenticator: ssh-keygen -t ed25519-sk creates it, and every login needs a touch. Nothing is installed on the server beyond a recent OpenSSH; the public key goes into authorized_keys like any other.

ssh-keygen -t ed25519-sk -C admin@laptop
ssh-copy-id -i ~/.ssh/id_ed25519_sk.pub admin@203.0.113.10

It is the right first step, and it is free. What it does not change is exposure: sshd still accepts connections from the whole internet and runs its pre-authentication code for each of them. A bug of the regreSSHion kind (CVE-2024-6387) is reached before any key is asked for.

2. A VPN in front

Put SSH on an address reachable only through a VPN, and port 22 disappears from the internet. WireGuard is especially good at this: it does not answer packets it cannot authenticate, so scanners do not see it either.

The price is a network to run: keys to distribute, routes, a client on every device, and trouble on guest networks that block UDP. And a WireGuard key is a file. There is no touch, no PIN and no second factor unless you add an identity layer on top.

3. Port knocking and single packet authorization

Classic port knocking (knockd) opens the port after a secret sequence of connection attempts. It hides the port, but the sequence travels in the clear and can be replayed by anyone who sees the traffic. Single packet authorization (fwknop) fixes that with one encrypted, non-replayable packet.

Both prove knowledge of a secret stored in a file on the client. Neither involves a hardware key or a person: malware on the admin's laptop can knock as well as the admin can.

4. A port that opens on a key touch

The newest variant keeps the idea of knocking and replaces the secret with a FIDO2 confirmation. The firewall drops the port; a small service verifies a WebAuthn signature from an enrolled key and opens the port for the caller's address for a short window.

RDP-FIDO-GATE works this way. On a Linux server sudo rdpfido-gate ports add 22 puts SSH — and up to 16 TCP ports — behind the same key that guards Remote Desktop, and the client starts ssh right after the touch. Setup takes about ten minutes: see the step-by-step guide.

There are also open-source projects that do the knock in a browser with a passkey. They need no client program; they do need a public HTTPS endpoint with a valid certificate on the server.

Side by side

ed25519-sk keysVPN (WireGuard)Knocking / SPAKey-gated port
Port 22 answers strangersYesNoNoNo
Key touch for each connectionYesNoNoYes
Shields sshd from pre-auth bugsNoYesYesYes
Extra software on the serverNoneVPN endpointknockd or fwknopdGate service
Extra software on the clientNone (OpenSSH 8.2+)VPN clientKnock clientGate client
Works where UDP is blockedYesOften notfwknop uses UDP by defaultYes (TLS over TCP)
New surface it exposesNoneA VPN port that stays silentNone, or a silent listenerThe gate port, which answers TLS
CostFreeFreeFreeFree up to 10 sessions, then a one-time licence

Which to choose

RDP-FIDO-GATE

RDP-FIDO-GATE keeps SSH and other admin ports closed and opens them for one IP, for about 90 seconds, only after a FIDO2 key touch or an authenticator code. Its client includes an SSH console with saved passwords, saved commands and an AI assistant that works with Claude or with your own local model. The Free edition covers 10 saved sessions.

Frequently asked questions

Is pam_u2f a fifth option?

Not for remote logins. pam_u2f talks to a key plugged into the machine that runs PAM — for SSH that is the server, not your laptop. It is a good fit for sudo and for local logins.

Can I use a gate and ed25519-sk keys together?

Yes, and it is the strongest setup of the four: the gate decides who may reach the port, sshd decides who may log in, and each asks for a key touch.

Does a key-gated port help if my IP address is shared?

The port opens for your public address. Others behind the same NAT could reach port 22 during the 90-second window and would still have to pass sshd. Everyone else on the internet stays blocked.

Which approach survives a stolen laptop?

The ones that need the hardware key at connection time: ed25519-sk keys and a key-gated port. A VPN profile or a knock key stored on the laptop goes with the laptop.

Related guides