{"thread":{"id":"58602","subject":"Error / feature-request: Signing git commits with SSH hardware key","startedAt":"2022-10-11T19:32:23Z","lastAt":"2022-10-12T12:10:53Z","messageCount":7,"participants":["Nicolas Graves","brian m. carlson","Fabian Stelzer"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"464630","messageId":"875ygqw7p8.fsf@ngraves.fr","threadId":"58602","inReplyTo":null,"subject":"Error / feature-request: Signing git commits with SSH hardware key","fromName":"Nicolas Graves","fromEmail":"ngraves@ngraves.fr","sentAt":"2022-10-11T18:12:19Z","receivedAt":"2022-10-11T19:32:23Z","isPatch":false,"sender":{"key":"ngraves@ngraves.fr","avatar":null},"body":"\nHi!\n\nI noticed git commit signing works well with ssh-ed25519 keys, but does\nfail with sk-ssh-ed25519@openssh.com SSH hardware keys (with can be\nused to clone / post to github for instance).\n\nWould that be possible to support in a later release? Thus having a\nsmart card can be useful for both ssh and git.\n\nI also noticed a similar error in a previous mail from Cuckoo Aidan\n<aidancuckoo@gmail.com>, but he doesn't say which type of key he\nused. In any case, would that be possible to include the info about\nwhich type of keys cannot be used to commit in the github guide\nhttps://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key) ?\n\n-- \nBest regards,\nNicolas Graves\n"},{"id":"464631","messageId":"Y0XVCDu9o3xDnt81@tapette.crustytoothpaste.net","threadId":"58602","inReplyTo":"875ygqw7p8.fsf@ngraves.fr","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2022-10-11T20:41:44Z","receivedAt":"2022-10-11T20:41:50Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2022-10-11 at 18:12:19, Nicolas Graves wrote:\n> \n> Hi!\n\nHey,\n\n> I noticed git commit signing works well with ssh-ed25519 keys, but does\n> fail with sk-ssh-ed25519@openssh.com SSH hardware keys (with can be\n> used to clone / post to github for instance).\n\nI was surprised to hear that, so I just tested on my Debian amd64/sid\nsystem, and I was able to sign and verify using an\nsk-ssh-ed25519@openssh.com SSH key using my YubiKey 5C.  I do believe it\ndoes work, although when the signature occurs, there's no notice that\nit's waiting for user interaction, so you just have to look at the\nlights to determine that the touch is needed.\n\nCould you maybe mention what version of OpenSSH you're using and on what\nplatform?  I used 9.0p1, and as I mentioned, it's Linux.  The output\nlooks like so:\n\n  $ git verify-commit --raw HEAD\n  Good \"git\" signature for sandals@crustytoothpaste.net with ED25519-SK key SHA256:PNxAWB7cxxxrCTbgsdoDq71o3rCm9O7Er4q+0YrEAdM\n\nSpecifically, what error message or other indications of failure do you\nsee when you try to sign?\n\n> I also noticed a similar error in a previous mail from Cuckoo Aidan\n> <aidancuckoo@gmail.com>, but he doesn't say which type of key he\n> used. In any case, would that be possible to include the info about\n> which type of keys cannot be used to commit in the github guide\n> https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key) ?\n\nWe don't control the GitHub documentation, since we're independent of\nGitHub.  If there's incorrect information, you'd need to contact GitHub.\nHowever, as I mentioned above, I do believe this works at least in some\ncases.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"},{"id":"464635","messageId":"87v8oquiuk.fsf@ngraves.fr","threadId":"58602","inReplyTo":"Y0XVCDu9o3xDnt81@tapette.crustytoothpaste.net","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"Nicolas Graves","fromEmail":"ngraves@ngraves.fr","sentAt":"2022-10-11T21:54:27Z","receivedAt":"2022-10-11T22:31:06Z","isPatch":false,"sender":{"key":"ngraves@ngraves.fr","avatar":null},"body":"\nOn 2022-10-11 20:41, brian m. carlson wrote:\n\n> Could you maybe mention what version of OpenSSH you're using and on what\n> platform?  I used 9.0p1, and as I mentioned, it's Linux.  The output\n> looks like so:\n\nI currently use this version on Guix (so Linux):\nOpenSSH_8.9p1, OpenSSL 1.1.1q  5 Jul 2022\n\nThe errors occurs when I try to \"really\" commit using magit or git\nthrough the command line.\n\nhint: Waiting for your editor to close the file...\nWaiting for Emacs...\nerror: Couldn't load public key sk-ssh-ed25519@openssh.com AAAAG[..]zaDo=: No such file or directory?\n\nfatal: failed to write commit object\n\n\nNow if I try this command:\n>   $ git verify-commit --raw HEAD\n\nI get the following:\nerror: gpg.ssh.allowedSignersFile needs to be configured and exist for ssh signature verification\n\n\nIt's possible that my config is not complete, I remember not having\nnecessarily done the part with allowedsigners (which is not necessary\nfor an ed25519 \"simple\" key apparently). I'll take a look, and come back\nto you. \n\n\n-- \nBest regards,\nNicolas Graves\n"},{"id":"464637","messageId":"87r0zeuhrv.fsf@ngraves.fr","threadId":"58602","inReplyTo":"87v8oquiuk.fsf@ngraves.fr","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"Nicolas Graves","fromEmail":"ngraves@ngraves.fr","sentAt":"2022-10-11T22:17:40Z","receivedAt":"2022-10-11T22:36:09Z","isPatch":false,"sender":{"key":"ngraves@ngraves.fr","avatar":null},"body":"On 2022-10-11 23:54, Nicolas Graves wrote:\n\n> error: gpg.ssh.allowedSignersFile needs to be configured and exist for ssh signature verification\n\nAnd I can confirm that it was this error and bad configuration, sorry!\n\n> error: Couldn't load public key sk-ssh-ed25519@openssh.com AAAAG[..]zaDo=: No such file or directory?\n\nThis error is not very precise though.\n\nThanks for your help!\n\n\n-- \nBest regards,\nNicolas Graves\n"},{"id":"464651","messageId":"87leplv8fr.fsf@ngraves.fr","threadId":"58602","inReplyTo":"87r0zeuhrv.fsf@ngraves.fr","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"Nicolas Graves","fromEmail":"ngraves@ngraves.fr","sentAt":"2022-10-12T06:54:00Z","receivedAt":"2022-10-12T06:54:10Z","isPatch":false,"sender":{"key":"ngraves@ngraves.fr","avatar":null},"body":"\n>> error: Couldn't load public key sk-ssh-ed25519@openssh.com AAAAG[..]zaDo=: No such file or directory?\n>\nSorry, I still do have this error, even though the previous one\ndisappeared (it verified a commit signed byb another key) and my\nconfiguration is OK.\n\nNo such file or directory would indicate I don't own the key. I've\nverified I have the key on my Yubikey5C, in the directory ~/.ssh with\nthe right condition, and additionnaly I've imported it in ssh-agent with\nssh-add.\n\nUsing the GIT_TRACE=2 env variable, I get this:\n08:32:41.916712 git.c:460               trace: built-in: git commit -m test\n08:32:41.917380 run-command.c:655       trace: run_command: ssh-keygen -Y sign -n git -f 'sk-ssh-ed25519@openssh.com AAAAG[...]zaDo=' /tmp/.git_signing_buffer_tmp6Dc0Mx\n\nThe ssh-keygen manual indicates the following:\n\n-Y sign\n             Cryptographically sign a file or some data using a SSH key.  When\n             signing, ssh-keygen accepts zero or more files to sign on the\n             command-line - if no files are specified then ssh-keygen will\n             sign data presented on standard input.  Signatures are written to\n             the path of the input file with “.sig” appended, or to standard\n             output if the message to be signed was read from standard input.\n\n             The key used for signing is specified using the -f option and may\n             refer to either a private key, or a public key with the private\n             half available via ssh-agent(1).  An additional signature name‐\n             space, used to prevent signature confusion across different do‐\n             mains of use (e.g. file signing vs email signing) must be pro‐\n             vided via the -n flag.  Namespaces are arbitrary strings, and may\n             include: “file” for file signing, “email” for email signing.  For\n             custom uses, it is recommended to use names following a NAME‐\n             SPACE@YOUR.DOMAIN pattern to generate unambiguous namespaces.\n\nRunning ssh-add -L, I can confirm that the private half is available via\nssh-agent.\n\nI've also check that the error doesn't come from the missing input file (used to\nsign), here /tmp/.git_signing_buffer_tmp6Dc0Mx . Re-running the\nssh-keygen command with a mock file fails with the same error.\n\nI don't really know where to investigate next. What I get is that the\nerror probably comes from ssh (should I report it there? The problem\nfeels isolated now that I know which command fails). I may try to\nupdate openssh to v9, but since I'm using guix that might be quick as\nwell as tedious.\n\n-- \nBest regards,\nNicolas Graves\n"},{"id":"464652","messageId":"20221012065541.y2tl63tw3ooeoy7s@fs","threadId":"58602","inReplyTo":"87r0zeuhrv.fsf@ngraves.fr","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2022-10-12T06:55:41Z","receivedAt":"2022-10-12T06:55:56Z","isPatch":false,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 12.10.2022 00:17, Nicolas Graves wrote:\n>On 2022-10-11 23:54, Nicolas Graves wrote:\n>\n>> error: gpg.ssh.allowedSignersFile needs to be configured and exist for ssh signature verification\n>\n>And I can confirm that it was this error and bad configuration, sorry!\n>\n>> error: Couldn't load public key sk-ssh-ed25519@openssh.com AAAAG[..]zaDo=: No such file or directory?\n>\n>This error is not very precise though.\n\nI assume you have specified your key in the git config in user.signingkey as \nthe literal keystring?\nIf so, then you'll need a `key::` prefix. Otherwise git will treat it as a \nfile path.\nSee \nhttps://git-scm.com/docs/git-config#Documentation/git-config.txt-usersigningKey\n\nIn the initial merge of this feature, git would allow ssh-* keys to be \nspecified without the prefix. This was later deprecated and not all \nTutorial/Docs you'll find online consider this.\n\nCheers,\nFabian\n\n>\n>Thanks for your help!\n>\n>\n>-- \n>Best regards,\n>Nicolas Graves\n"},{"id":"464694","messageId":"871qrdh5ff.fsf@ngraves.fr","threadId":"58602","inReplyTo":"20221012065541.y2tl63tw3ooeoy7s@fs","subject":"Re: Error / feature-request: Signing git commits with SSH hardware key","fromName":"Nicolas Graves","fromEmail":"ngraves@ngraves.fr","sentAt":"2022-10-12T07:22:44Z","receivedAt":"2022-10-12T12:10:53Z","isPatch":false,"sender":{"key":"ngraves@ngraves.fr","avatar":null},"body":"On 2022-10-12 08:55, Fabian Stelzer wrote:\n\n> I assume you have specified your key in the git config in user.signingkey as\n> the literal keystring?\n> If so, then you'll need a `key::` prefix. Otherwise git will treat it as a\n> file path.\n> See\n> https://git-scm.com/docs/git-config#Documentation/git-config.txt-usersigningKey\n>\n> In the initial merge of this feature, git would allow ssh-* keys to be\n> specified without the prefix. This was later deprecated and not all\n> Tutorial/Docs you'll find online consider this.\n\nOur mails crossed :)\n\nThis was the actual error, thanks a lot!\n\n-- \nBest regards,\nNicolas Graves\n"}]}