Hi, Markus Friedl has added PKCS#11 support for ECDSA keys to OpenSSH. It's available in OpenBSD and the portable version and includes a regress test against softhsm2. https://anongit.mindrot.org/openssh.git/commit/?id=93f02107 (and subsequent) I've used it successfully with a Yubikey 4 using RSA2048, ECCP256 and ECCP384 keys. This should be in the OpenSSH 8.0 release. -d _______________________________________________ openssh-unix-dev mailing list openssh-unix-dev@xxxxxxxxxxx https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev