{"thread":{"id":"62463","subject":"gpg-ssh signing with AgentForwarding","startedAt":"2024-11-07T04:17:13Z","lastAt":"2024-11-14T08:58:00Z","messageCount":4,"participants":["Yarden Bar","Fabian Stelzer","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"506778","messageId":"CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com","threadId":"62463","inReplyTo":null,"subject":"gpg-ssh signing with AgentForwarding","fromName":"Yarden Bar","fromEmail":"ayash.jorden@gmail.com","sentAt":"2024-11-07T04:16:34Z","receivedAt":"2024-11-07T04:17:13Z","isPatch":false,"sender":{"key":"ayash.jorden@gmail.com","avatar":null},"body":"Hello Git community,\nNot sure what search terms I haven't used, but I'll try to describe the use-case\n\nOn my local machine I have a SSH key, and I use AgentForwarding when I\ngo out and about to other hosts (dev machines)\nThe usual workflow of using the forwarded socket works for pull and push.\n\nWhere it gets pitch-dark is when I try to use my ssh key to sign git commits.\nFollowing is my git config on the remote host:\n=====================\n[user]\n    name = John Doe\n    email = jdoe@jdoe.com\n# on my local machine(gpg-ssh signing works): signingkey =\n/Users/jdoe/.ssh/id_ecdsa.pub\n    signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to\nthe public key from Secretive, or just omit it?\n[gpg]\n    format = ssh\n[commit]\n    gpgsign = true\n[gpg \"ssh\"]\n    allowedSignersFile = /Users/jdoe/.gpg.ssh.allowedSignersFile #\ncontents is: \"email1,email2 key-type public_key comment\"\n=====================\n\nI've tried\n1. `ssh-agent -a /path/to/ssh.sock` - errored with address already in use\n2. signingkey set to a path on the remote host with my public key,\nerrored with \"no private key found\"\n\nI sense that I should be able to employ `gpg.ssh.defaultKeyCommand` to\nuse the socket somehow, but I can't wrap my head around it or find\nsome docs/guidance.\n\nOther (related) links\nhttps://developer.1password.com/docs/ssh/git-commit-signing/ - I think\nthat 1Password invested the time to make it work\nhttps://github.com/maxgoedjen/secretive/discussions/338#discussioncomment-11170722\n- asked the same on Secretive repo, which is one way to store keys\nhttps://github.com/maxgoedjen/secretive/issues/405#issuecomment-2460948732\n- also here.\n\nThank you,\nJordan\n"},{"id":"506783","messageId":"oeic2p6av3b65mibwmtmiiiciduufysqw4wekileu2tlch3ryx@uqtxefn2wuf5","threadId":"62463","inReplyTo":"CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com","subject":"Re: gpg-ssh signing with AgentForwarding","fromName":"Fabian Stelzer","fromEmail":"fs@gigacodes.de","sentAt":"2024-11-07T09:07:42Z","receivedAt":"2024-11-07T09:07:46Z","isPatch":false,"sender":{"key":"fs@gigacodes.de","avatar":"https://avatars.githubusercontent.com/u/564858?v=4"},"body":"On 06.11.2024 20:16, Yarden Bar wrote:\n>Hello Git community,\n>Not sure what search terms I haven't used, but I'll try to describe the use-case\n>\n>On my local machine I have a SSH key, and I use AgentForwarding when I\n>go out and about to other hosts (dev machines)\n>The usual workflow of using the forwarded socket works for pull and push.\n>\n>Where it gets pitch-dark is when I try to use my ssh key to sign git commits.\n>Following is my git config on the remote host:\n\nHi Jordan,\nthe process on the remote host is pretty much identical to your local one as \nlong as the AgentForwarding works. When pull/push work so should the \nsigning.\nOne small caveat for older remote machines can be that you'll need a \nsomewhat recent openssh version. Default redhat 7 or 8 for example will not \nwork.\nThe ssh-keygen command needs the `-Y sign|verify` commands. If the remote is \ntoo old you can place a newer ssh-keygen there yourself and reference it in \nyour git config via gpg.ssh.program\n\n>=====================\n>[user]\n>    name = John Doe\n>    email = jdoe@jdoe.com\n># on my local machine(gpg-ssh signing works): signingkey =\n>/Users/jdoe/.ssh/id_ecdsa.pub\n>    signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to\n>the public key from Secretive, or just omit it?\n\nA path to your public key file or the literal key prefixed with key:: is \nfine.\n\n>[gpg]\n>    format = ssh\n>[commit]\n>    gpgsign = true\n>[gpg \"ssh\"]\n>    allowedSignersFile = /Users/jdoe/.gpg.ssh.allowedSignersFile #\n>contents is: \"email1,email2 key-type public_key comment\"\n>=====================\n>\n>I've tried\n>1. `ssh-agent -a /path/to/ssh.sock` - errored with address already in use\n>2. signingkey set to a path on the remote host with my public key,\n>errored with \"no private key found\"\n>\n>I sense that I should be able to employ `gpg.ssh.defaultKeyCommand` to\n>use the socket somehow, but I can't wrap my head around it or find\n>some docs/guidance.\n\nNo need for defaultKeyCommand and no need to start another agent on the \nremote host.\nIf you get the \"no private key found\" error then the connection to the ssh \nagent does not work. (Maybe because you started another on the remote?)\nYou can test this easily by running \"ssh-add -l\" on the remote host which \nshould print your public keys from the agent.\n\nKind regards,\nFabian\n\n>\n>Other (related) links\n>https://developer.1password.com/docs/ssh/git-commit-signing/ - I think\n>that 1Password invested the time to make it work\n>https://github.com/maxgoedjen/secretive/discussions/338#discussioncomment-11170722\n>- asked the same on Secretive repo, which is one way to store keys\n>https://github.com/maxgoedjen/secretive/issues/405#issuecomment-2460948732\n>- also here.\n>\n>Thank you,\n>Jordan\n>\n"},{"id":"506785","messageId":"ZyybBPigKZ_MlnU6@tapette.crustytoothpaste.net","threadId":"62463","inReplyTo":"CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com","subject":"Re: gpg-ssh signing with AgentForwarding","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2024-11-07T10:48:36Z","receivedAt":"2024-11-07T10:48:43Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2024-11-07 at 04:16:34, Yarden Bar wrote:\n> Hello Git community,\n> Not sure what search terms I haven't used, but I'll try to describe the use-case\n> \n> On my local machine I have a SSH key, and I use AgentForwarding when I\n> go out and about to other hosts (dev machines)\n> The usual workflow of using the forwarded socket works for pull and push.\n> \n> Where it gets pitch-dark is when I try to use my ssh key to sign git commits.\n> Following is my git config on the remote host:\n> =====================\n> [user]\n>     name = John Doe\n>     email = jdoe@jdoe.com\n> # on my local machine(gpg-ssh signing works): signingkey =\n> /Users/jdoe/.ssh/id_ecdsa.pub\n>     signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to\n> the public key from Secretive, or just omit it?\n\nI think you want something like this:\n\n  [user]\n      signingkey = \"key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl\"\n\nYou should use your own key; that's just an example.  Note that you want\nthe public key (that is, what's in `id_ecdsa.pub`, not `id_ecdsa`).\n\nOnce you have the key in the config file like that, with the \"key::\"\nprefix, Git will pull from the agent if necessary.  I do that for\nsigning commits using GitHub Codespaces, where it's easier to forward\nan SSH agent to the remote system than with GnuPG.\n\nThis is documented in the `user.signingKey` entry in `git config\n--help`, but if there's something there that's unclear or you think the\ntext could be improved, please say something, and we'll try to get it\nfixed.\n-- \nbrian m. carlson (they/them or he/him)\nToronto, Ontario, CA\n"},{"id":"507258","messageId":"CAJPGt+WwMWApt5o8E1nQGZnADbfjEkVmazUmxJ83Au6QPJ8Jdg@mail.gmail.com","threadId":"62463","inReplyTo":"ZyybBPigKZ_MlnU6@tapette.crustytoothpaste.net","subject":"Re: gpg-ssh signing with AgentForwarding","fromName":"Yarden Bar","fromEmail":"ayash.jorden@gmail.com","sentAt":"2024-11-14T08:57:22Z","receivedAt":"2024-11-14T08:58:00Z","isPatch":false,"sender":{"key":"ayash.jorden@gmail.com","avatar":null},"body":"Hi all,\nA colleague of mine was able to figure it out.\nhttps://github.com/maxgoedjen/secretive/issues/405#issuecomment-2475175801\nHope it will help/serve the community\n\nJordan\n\nOn Thu, Nov 7, 2024 at 2:48 AM brian m. carlson\n<sandals@crustytoothpaste.net> wrote:\n>\n> On 2024-11-07 at 04:16:34, Yarden Bar wrote:\n> > Hello Git community,\n> > Not sure what search terms I haven't used, but I'll try to describe the use-case\n> >\n> > On my local machine I have a SSH key, and I use AgentForwarding when I\n> > go out and about to other hosts (dev machines)\n> > The usual workflow of using the forwarded socket works for pull and push.\n> >\n> > Where it gets pitch-dark is when I try to use my ssh key to sign git commits.\n> > Following is my git config on the remote host:\n> > =====================\n> > [user]\n> >     name = John Doe\n> >     email = jdoe@jdoe.com\n> > # on my local machine(gpg-ssh signing works): signingkey =\n> > /Users/jdoe/.ssh/id_ecdsa.pub\n> >     signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to\n> > the public key from Secretive, or just omit it?\n>\n> I think you want something like this:\n>\n>   [user]\n>       signingkey = \"key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl\"\n>\n> You should use your own key; that's just an example.  Note that you want\n> the public key (that is, what's in `id_ecdsa.pub`, not `id_ecdsa`).\n>\n> Once you have the key in the config file like that, with the \"key::\"\n> prefix, Git will pull from the agent if necessary.  I do that for\n> signing commits using GitHub Codespaces, where it's easier to forward\n> an SSH agent to the remote system than with GnuPG.\n>\n> This is documented in the `user.signingKey` entry in `git config\n> --help`, but if there's something there that's unclear or you think the\n> text could be improved, please say something, and we'll try to get it\n> fixed.\n> --\n> brian m. carlson (they/them or he/him)\n> Toronto, Ontario, CA\n"}]}