{"thread":{"id":"58075","subject":"Unable to use security key to commit signing using SSH keypair","startedAt":"2022-06-28T00:09:39Z","lastAt":"2022-06-28T16:50:42Z","messageCount":3,"participants":["Marcos Alano","Fabian Stelzer"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"457981","messageId":"97adcd90-b4d3-1114-205b-3445dd48b497@gmail.com","threadId":"58075","inReplyTo":null,"subject":"Unable to use security key to commit signing using SSH keypair","fromName":"Marcos Alano","fromEmail":"marcoshalano@gmail.com","sentAt":"2022-06-28T00:09:32Z","receivedAt":"2022-06-28T00:09:39Z","isPatch":false,"sender":{"key":"marcoshalano@gmail.com","avatar":"https://gravatar.com/avatar/e9d7f22abbfb2fcde753aab73d4ffb91d9a9df10f246fa7945ab3d3cc905684d?d=mp&s=160"},"body":"Hello fellows!\n\nI'm able to sign commits using SSH keypair, but the keypair must be \nlocated in a file. If I try to use a SSH keypair in a security key (like \nan YubiKey) I get an error. I used this commands to do the test:\n```\nssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk\ngit config --global gpg.format ssh\ngit config --global user.signingkey \"$(cat ~/.ssh/id_ed25519_sk.pub)\"\ngit commit -S --allow-empty --message=\"Testing\"\n```\n\nBnd I get this error:\n```\nerror: Couldn't load public key sk-ssh-ed25519@openssh.com <my key id>: \nNo such file or directory?\n\nfatal: failed to write commit object\n```\nI did the same thing with a plain ed25519 keypair and worked.\n\nAm I doing anything wrong or security keys aren't supported yet?\n\nThank you for any help,\n-- \nMarcos Alano\n"},{"id":"458047","messageId":"20220628162342.ootjobbjtxg7b7ay@fs","threadId":"58075","inReplyTo":"97adcd90-b4d3-1114-205b-3445dd48b497@gmail.com","subject":"Re: Unable to use security key to commit signing using SSH keypair","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-06-28T16:23:42Z","receivedAt":"2022-06-28T16:32:56Z","isPatch":false,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 27.06.2022 21:09, Marcos Alano wrote:\n>Hello fellows!\n>\n>I'm able to sign commits using SSH keypair, but the keypair must be \n>located in a file. If I try to use a SSH keypair in a security key \n>(like an YubiKey) I get an error. I used this commands to do the test:\n>```\n>ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk\n>git config --global gpg.format ssh\n>git config --global user.signingkey \"$(cat ~/.ssh/id_ed25519_sk.pub)\"\n\nDid you try just putting the public keys path into user.signingkey?\nLiteral keys would need to be prefixed with `key::`\n\ngit config --global user.signingkey ~/.ssh/id_ed25519_sk.pub\nshould be just fine.\n\nAlso, the private key needs to be available in your ssh agent. If in doubt \nyou can check with a `ssh-add -L`.\n\n>git commit -S --allow-empty --message=\"Testing\"\n>```\n>\n>Bnd I get this error:\n>```\n>error: Couldn't load public key sk-ssh-ed25519@openssh.com <my key \n>id>: No such file or directory?\n>\n>fatal: failed to write commit object\n>```\n>I did the same thing with a plain ed25519 keypair and worked.\n>\n>Am I doing anything wrong or security keys aren't supported yet?\n>\n>Thank you for any help,\n>-- \n>Marcos Alano\n"},{"id":"458049","messageId":"671b375c-66e5-0164-3625-4ccfa57ece95@gmail.com","threadId":"58075","inReplyTo":"20220628162342.ootjobbjtxg7b7ay@fs","subject":"Re: Unable to use security key to commit signing using SSH keypair","fromName":"Marcos Alano","fromEmail":"marcoshalano@gmail.com","sentAt":"2022-06-28T16:43:43Z","receivedAt":"2022-06-28T16:50:42Z","isPatch":false,"sender":{"key":"marcoshalano@gmail.com","avatar":"https://gravatar.com/avatar/e9d7f22abbfb2fcde753aab73d4ffb91d9a9df10f246fa7945ab3d3cc905684d?d=mp&s=160"},"body":"On 28/06/2022 13:23, Fabian Stelzer wrote:\n> On 27.06.2022 21:09, Marcos Alano wrote:\n>> Hello fellows!\n>>\n>> I'm able to sign commits using SSH keypair, but the keypair must be \n>> located in a file. If I try to use a SSH keypair in a security key \n>> (like an YubiKey) I get an error. I used this commands to do the test:\n>> ```\n>> ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk\n>> git config --global gpg.format ssh\n>> git config --global user.signingkey \"$(cat ~/.ssh/id_ed25519_sk.pub)\"\n> \n> Did you try just putting the public keys path into user.signingkey?\n> Literal keys would need to be prefixed with `key::`\n> \nThank you, worked like a charm. Every documentation I read told me to \nuse the plain public key, without the path or the prefix you indicated. \nAnd worked well with a regular keypair.\n\nUsing the path and prefixing the public key worked.\n\nYou have my gratitude. :)\n\nStay well,\n> git config --global user.signingkey ~/.ssh/id_ed25519_sk.pub\n> should be just fine.\n> \n> Also, the private key needs to be available in your ssh agent. If in \n> doubt you can check with a `ssh-add -L`.\n> \n>> git commit -S --allow-empty --message=\"Testing\"\n>> ```\n>>\n>> Bnd I get this error:\n>> ```\n>> error: Couldn't load public key sk-ssh-ed25519@openssh.com <my key \n>> id>: No such file or directory?\n>>\n>> fatal: failed to write commit object\n>> ```\n>> I did the same thing with a plain ed25519 keypair and worked.\n>>\n>> Am I doing anything wrong or security keys aren't supported yet?\n>>\n>> Thank you for any help,\n>> -- \n>> Marcos Alano\n\n-- \nMarcos Alano\n\n"}]}