{"thread":{"id":"62105","subject":"Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent","startedAt":"2024-09-13T09:59:24Z","lastAt":"2024-09-14T16:09:25Z","messageCount":3,"participants":["Justin Su","Phillip Wood"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"502745","messageId":"CAB=S_8JhN=WSuYRMWbGz7gZMRX9dSb3k8rJZ7zrxkbHKOqfzww@mail.gmail.com","threadId":"62105","inReplyTo":null,"subject":"Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent","fromName":"Justin Su","fromEmail":"injustsu@gmail.com","sentAt":"2024-09-13T09:58:45Z","receivedAt":"2024-09-13T09:59:24Z","isPatch":false,"sender":{"key":"injustsu@gmail.com","avatar":"https://gravatar.com/avatar/038335c7765082d30381cabb16967c569c317af7c4d49addc996dcf9720ada06?d=mp&s=160"},"body":"I use Secretive (https://github.com/maxgoedjen/secretive) to store my\nSSH keys on macOS. I've configured my ssh_config to use it as the\nIdentityAgent, and Git can push and pull just fine.\n\nHowever, it seems that Git ignores IdentityAgent when signing commits,\nresulting in the following error message:\n\nerror: No private key found for public key \"foo.pub\"?\nfatal: failed to write commit object\n\nI've worked around this by setting SSH_AUTH_SOCK, but this doesn't\nfeel correct to me. Is this intended behaviour?\n\nThanks,\nJustin\n"},{"id":"502754","messageId":"a25f71ad-093f-4e8d-97ef-503bfb9926d2@gmail.com","threadId":"62105","inReplyTo":"CAB=S_8JhN=WSuYRMWbGz7gZMRX9dSb3k8rJZ7zrxkbHKOqfzww@mail.gmail.com","subject":"Re: Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent","fromName":"Phillip Wood","fromEmail":"phillip.wood123@gmail.com","sentAt":"2024-09-13T15:05:13Z","receivedAt":"2024-09-13T15:05:17Z","isPatch":false,"sender":{"key":"phillip.wood@dunelm.org.uk","avatar":null},"body":"Hi Justin\n\nOn 13/09/2024 10:58, Justin Su wrote:\n> I use Secretive (https://github.com/maxgoedjen/secretive) to store my\n> SSH keys on macOS. I've configured my ssh_config to use it as the\n> IdentityAgent, and Git can push and pull just fine.\n> \n> However, it seems that Git ignores IdentityAgent when signing commits,\n> resulting in the following error message:\n\nGit just runs \"ssh -Y\". I can reproduce this on linux - I suspect the \nproblem is that ssh does not read the IdentityAgent config when signing \neven if it is outside a Host/Match in the config file.\n\nBest Wishes\n\nPhillip\n\n> error: No private key found for public key \"foo.pub\"?\n> fatal: failed to write commit object\n> \n> I've worked around this by setting SSH_AUTH_SOCK, but this doesn't\n> feel correct to me. Is this intended behaviour?\n> \n> Thanks,\n> Justin\n> \n"},{"id":"502789","messageId":"CAB=S_8+SAYVBNPByMrgmPQtA9JKmKt+kmeRBB=9=bSR2LLiMkw@mail.gmail.com","threadId":"62105","inReplyTo":"a25f71ad-093f-4e8d-97ef-503bfb9926d2@gmail.com","subject":"Re: Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent","fromName":"Justin Su","fromEmail":"injustsu@gmail.com","sentAt":"2024-09-14T16:08:48Z","receivedAt":"2024-09-14T16:09:25Z","isPatch":false,"sender":{"key":"injustsu@gmail.com","avatar":"https://gravatar.com/avatar/038335c7765082d30381cabb16967c569c317af7c4d49addc996dcf9720ada06?d=mp&s=160"},"body":"On Fri, Sep 13, 2024 at 11:05 AM Phillip Wood <phillip.wood123@gmail.com> wrote:\n>\n> Hi Justin\n>\n> On 13/09/2024 10:58, Justin Su wrote:\n> > I use Secretive (https://github.com/maxgoedjen/secretive) to store my\n> > SSH keys on macOS. I've configured my ssh_config to use it as the\n> > IdentityAgent, and Git can push and pull just fine.\n> >\n> > However, it seems that Git ignores IdentityAgent when signing commits,\n> > resulting in the following error message:\n>\n> Git just runs \"ssh -Y\". I can reproduce this on linux - I suspect the\n> problem is that ssh does not read the IdentityAgent config when signing\n> even if it is outside a Host/Match in the config file.\n\nAgreed, this seems like a ssh-keygen limitation. I reproduced this\ndirectly with ssh-keygen on macOS.\n\nAccording to its man page, if you pass a public key for the `-f`\noption, then the private half needs to be available via ssh-agent. The\nman page doesn't mention SSH_AUTH_SOCK either, but I guess it's the\nbest solution for my use case.\n\n> Best Wishes\n>\n> Phillip\n>\n> > error: No private key found for public key \"foo.pub\"?\n> > fatal: failed to write commit object\n> >\n> > I've worked around this by setting SSH_AUTH_SOCK, but this doesn't\n> > feel correct to me. Is this intended behaviour?\n> >\n> > Thanks,\n> > Justin\n> >\n"}]}