I've got a Yubikey 5 NFC and I've set it up for ssh authentication on several hosts. I've been able to auth successfully on Mac and Windows computers, however it doesn't work on Chromeos.
I've installed hterm and smart card connector. Smart card connector detects the yubikey, it shows up as "Yubico Yubikey OTP+FIDO+CCID". I've set up a profile in hterm with "--ssh-agent=gsc", and when I attempt to use it "Secure Shell App" appears in "Connected Apps". I click to allow it to use the smart card connector. However, I am never prompted for a PIN and ssh does not appear to attempt the key from the yubikey.
I added a -v to the ssh command line options and I can see it never attempts the yubikey key, and since there's no other keys available and the server is configured for pubkey only auth fails. Has anyone encountered this issue or have any idea how to further debug? Ssh -v output follows.
Loading NaCl plugin... done.
Connecting to ??????????????????...
OpenSSH_7.9p1, OpenSSL 1.0.2k 26 Jan 2017
debug1: Connecting to ??????????????????.
debug1: Connection established.
debug1: getpeername failed: No such file or directory
debug1: identity file /.ssh/id_rsa type -1
debug1: identity file /.ssh/id_rsa-cert type -1
debug1: identity file /.ssh/id_dsa type -1
debug1: identity file /.ssh/id_dsa-cert type -1
debug1: identity file /.ssh/id_ecdsa type -1
debug1: identity file /.ssh/id_ecdsa-cert type -1
debug1: identity file /.ssh/id_ed25519 type -1
debug1: identity file /.ssh/id_ed25519-cert type -1
debug1: identity file /.ssh/id_xmss type -1
debug1: identity file /.ssh/id_xmss-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_7.9
debug1: Remote protocol version 2.0, remote software version OpenSSH_7.6p1 Ubuntu-4ubuntu0.3
debug1: match: OpenSSH_7.6p1 Ubuntu-4ubuntu0.3 pat OpenSSH_7.0*,OpenSSH_7.1*,OpenSSH_7.2*,OpenSSH_7.3*,OpenSSH_7.4*,OpenSSH_7.5*,OpenSSH_7.6*,OpenSSH_7.7* compat 0x04000002
debug1: Authenticating to ?????????????????? as '?????????'
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ecdsa-sha2-nistp256
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: Server host key: ecdsa-sha2-nistp256 SHA256:????????????????????
debug1: Host '??????????????????' is known and matches the ECDSA host key.
debug1: Found key in /.ssh/known_hosts:2
debug1: rekey after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey after 134217728 blocks
debug1: Will attempt key: /.ssh/id_rsa
debug1: Will attempt key: /.ssh/id_dsa
debug1: Will attempt key: /.ssh/id_ecdsa
debug1: Will attempt key: /.ssh/id_ed25519
debug1: Will attempt key: /.ssh/id_xmss
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521>
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey
debug1: Next authentication method: publickey
debug1: Trying private key: /.ssh/id_rsa
debug1: Trying private key: /.ssh/id_dsa
debug1: Trying private key: /.ssh/id_ecdsa
debug1: Trying private key: /.ssh/id_ed25519
debug1: Trying private key: /.ssh/id_xmss
debug1: No more authentication methods to try.
??????????????????: Permission denied (publickey).
NaCl plugin exited with status code 255.
(R)econnect, (C)hoose another connection, or E(x)it?
failed! :(