<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Support for FIDO/U2F in SSH in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257493#M43379</link>
    <description>&lt;P&gt;There may be more involved than that.&lt;BR /&gt;For formal support, it's probably going to require an &lt;A href="https://usercenter.checkpoint.com/ucapps/rfe/" target="_self"&gt;RFE&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 14:25:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-09-17T14:25:47Z</dc:date>
    <item>
      <title>Support for FIDO/U2F in SSH</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257191#M43315</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to use my YubiKey to connect to a Check Point appliance via SSH. My goal is to use &lt;STRONG&gt;FIDO2&lt;/STRONG&gt; [1], which is the recommended protocol for strong authentication. Unfortunately, this does not work.&lt;/P&gt;&lt;P&gt;When I connect to modern Linux distributions (Ubuntu, Oracle Linux, Debian, etc.), YubiKey with FIDO2 works correctly. However, I cannot establish an SSH connection to the Check Point appliance.&lt;/P&gt;&lt;P&gt;After some research, it seems that the issue is related to the SSH version currently used by Check Point. In our environment, we are running version &lt;STRONG&gt;R81.20&lt;/STRONG&gt;, which ships with &lt;STRONG&gt;OpenSSH 7.8&lt;/STRONG&gt;. This version is outdated, having been released back in 2018 [3]. FIDO2 support was only introduced in &lt;STRONG&gt;OpenSSH 8.2&lt;/STRONG&gt;, released in 2020 [2].&lt;/P&gt;&lt;P&gt;Could you please confirm if there are any plans to upgrade the OpenSSH version used in Check Point appliances, or at least to add FIDO2 support? FIDO2 is a modern, secure authentication protocol, and as a leading security vendor, Check Point should strongly consider supporting it as soon as possible.&lt;/P&gt;&lt;P&gt;Thank you for your support.&lt;/P&gt;&lt;P&gt;[1] &lt;A class="" href="https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html" target="_new" rel="noopener"&gt;https://developers.yubico.com/SSH/Securing_SSH_with_FIDO2.html&lt;/A&gt;&lt;BR /&gt;[2] &lt;A class="" href="https://www.openssh.com/txt/release-8.2" target="_new" rel="noopener"&gt;https://www.openssh.com/txt/release-8.2&lt;/A&gt;&lt;BR /&gt;[3] &lt;A class="" href="https://www.openssh.com/txt/release-7.8" target="_new" rel="noopener"&gt;https://www.openssh.com/txt/release-7.8&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 21:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257191#M43315</guid>
      <dc:creator>Ribas</dc:creator>
      <dc:date>2025-09-12T21:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Support for FIDO/U2F in SSH</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257493#M43379</link>
      <description>&lt;P&gt;There may be more involved than that.&lt;BR /&gt;For formal support, it's probably going to require an &lt;A href="https://usercenter.checkpoint.com/ucapps/rfe/" target="_self"&gt;RFE&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 14:25:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257493#M43379</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-17T14:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Support for FIDO/U2F in SSH</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257543#M43399</link>
      <description>&lt;P&gt;I actually showed this post on zoom session I had with TAC today on totally unrelated issue and guy said this would 100% be an RFE, so thats definitely your best bet.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 20:08:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Support-for-FIDO-U2F-in-SSH/m-p/257543#M43399</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-17T20:08:51Z</dc:date>
    </item>
  </channel>
</rss>

