git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 5/6] ssh signing: make verify-tag consider key lifetime

From
Fabian Stelzer <fs@gigacodes.de>
Date
Oct 27, 2021, 08:06 UTC
Message-ID
<20211027080616.619956-6-fs@gigacodes.de>
In-Reply-To
<20211027080616.619956-1-fs@gigacodes.de>

Set the payload_type for check_signature() when calling verify-tag. Implements the same tests as for verify-commit.

Signed-off-by: Fabian Stelzer <fs@gigacodes.de>
---
 t/t7031-verify-tag-signed-ssh.sh | 42 ++++++++++++++++++++++++++++++++
 tag.c                            |  1 +
 2 files changed, 43 insertions(+)
diff --git a/t/t7031-verify-tag-signed-ssh.sh b/t/t7031-verify-tag-signed-ssh.sh
index 06c9dd6c93..1cb36b9ab8 100755
--- a/t/t7031-verify-tag-signed-ssh.sh
+++ b/t/t7031-verify-tag-signed-ssh.sh
@@ -48,6 +48,23 @@ test_expect_success GPGSSH 'create signed tags ssh' '
 	git tag -u"${GPGSSH_KEY_UNTRUSTED}" -m eighth eighth-signed-alt
 '
 
+test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'create signed tags with keys having defined lifetimes' '
+	test_when_finished "test_unconfig commit.gpgsign" &&
+	test_config gpg.format ssh &&
+
+	echo expired >file && test_tick && git commit -a -m expired -S"${GPGSSH_KEY_EXPIRED}" &&
+	git tag -s -u "${GPGSSH_KEY_EXPIRED}" -m expired-signed expired-signed &&
+
+	echo notyetvalid >file && test_tick && git commit -a -m notyetvalid -S"${GPGSSH_KEY_NOTYETVALID}" &&
+	git tag -s -u "${GPGSSH_KEY_NOTYETVALID}" -m notyetvalid-signed notyetvalid-signed &&
+
+	echo timeboxedvalid >file && test_tick && git commit -a -m timeboxedvalid -S"${GPGSSH_KEY_TIMEBOXEDVALID}" &&
+	git tag -s -u "${GPGSSH_KEY_TIMEBOXEDVALID}" -m timeboxedvalid-signed timeboxedvalid-signed &&
+
+	echo timeboxedinvalid >file && test_tick && git commit -a -m timeboxedinvalid -S"${GPGSSH_KEY_TIMEBOXEDINVALID}" &&
+	git tag -s -u "${GPGSSH_KEY_TIMEBOXEDINVALID}" -m timeboxedinvalid-signed timeboxedinvalid-signed
+'
+
 test_expect_success GPGSSH 'verify and show ssh signatures' '
 	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
 	(
@@ -80,6 +97,31 @@ test_expect_success GPGSSH 'verify and show ssh signatures' '
 	)
 '
 
+test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'verify-tag exits failure on expired signature key' '
+	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
+	test_must_fail git verify-tag expired-signed 2>actual &&
+	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual
+'
+
+test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'verify-tag exits failure on not yet valid signature key' '
+	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
+	test_must_fail git verify-tag notyetvalid-signed 2>actual &&
+	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual
+'
+
+test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'verify-tag succeeds with tag date and key validity matching' '
+	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
+	git verify-tag timeboxedvalid-signed 2>actual &&
+	grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual &&
+	! grep "${GPGSSH_BAD_SIGNATURE}" actual
+'
+
+test_expect_success GPGSSH,GPGSSH_VERIFYTIME 'verify-tag failes with tag date outside of key validity' '
+	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
+	test_must_fail git verify-tag timeboxedinvalid-signed 2>actual &&
+	! grep "${GPGSSH_GOOD_SIGNATURE_TRUSTED}" actual
+'
+
 test_expect_success GPGSSH 'detect fudged ssh signature' '
 	test_config gpg.ssh.allowedSignersFile "${GPGSSH_ALLOWED_SIGNERS}" &&
 	git cat-file tag seventh-signed >raw &&
diff --git a/tag.c b/tag.c
index 62fb09f5a5..dfbcd7fcc2 100644
--- a/tag.c
+++ b/tag.c
@@ -25,6 +25,7 @@ static int run_gpg_verify(const char *buf, unsigned long size, unsigned flags)
 		return error("no signature found");
 	}
 
+	sigc.payload_type = SIGNATURE_PAYLOAD_TAG;
 	sigc.payload = strbuf_detach(&payload, &sigc.payload_len);
 	ret = check_signature(&sigc, signature.buf, signature.len);
 
-- 
2.31.1
Previous: Fabian StelzerNext: Adam Dinwoodie
Message 55 of 60 in “ssh signing: verify key lifetime”
  1. 0/6 ssh signing: verify key lifetimeFabian Stelzer, Oct 27, 2021
  2. 1/6 ssh signing: use sigc struct to pass payloadFabian Stelzer, Oct 27, 2021
  3. 2/6 ssh signing: add key lifetime test prereqsFabian Stelzer, Oct 27, 2021
  4. 3/6 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Oct 27, 2021
  5. Junio C HamanoOct 27, 2021
  6. Fabian StelzerOct 28, 2021
  7. 0/7 ssh signing: verify key lifetimeFabian Stelzer, Nov 17, 2021
  8. 1/7 ssh signing: use sigc struct to pass payloadFabian Stelzer, Nov 17, 2021
  9. 2/7 ssh signing: add key lifetime test prereqsFabian Stelzer, Nov 17, 2021
  10. 3/7 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Nov 17, 2021
  11. 4/7 ssh signing: make git log verify key lifetimeFabian Stelzer, Nov 17, 2021
  12. 5/7 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Nov 17, 2021
  13. 6/7 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Nov 17, 2021
  14. 7/7 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Nov 17, 2021
  15. Junio C HamanoNov 19, 2021
  16. 0/7 ssh signing: verify key lifetimeFabian Stelzer, Nov 30, 2021
  17. 1/7 ssh signing: use sigc struct to pass payloadFabian Stelzer, Nov 30, 2021
  18. 2/7 ssh signing: add key lifetime test prereqsFabian Stelzer, Nov 30, 2021
  19. 3/7 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Nov 30, 2021
  20. 4/7 ssh signing: make git log verify key lifetimeFabian Stelzer, Nov 30, 2021
  21. 5/7 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Nov 30, 2021
  22. 6/7 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Nov 30, 2021
  23. SZEDER GáborDec 5, 2021
  24. Fabian StelzerDec 8, 2021
  25. 7/7 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Nov 30, 2021
  26. Junio C HamanoDec 2, 2021
  27. Fabian StelzerDec 2, 2021
  28. Junio C HamanoDec 2, 2021
  29. Ævar Arnfjörð BjarmasonDec 3, 2021
  30. Fabian StelzerDec 3, 2021
  31. Junio C HamanoDec 3, 2021
  32. 0/8 ssh signing: verify key lifetimeFabian Stelzer, Dec 8, 2021
  33. 1/8 ssh signing: use sigc struct to pass payloadFabian Stelzer, Dec 8, 2021
  34. 2/8 ssh signing: add key lifetime test prereqsFabian Stelzer, Dec 8, 2021
  35. 3/8 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Dec 8, 2021
  36. 4/8 ssh signing: make git log verify key lifetimeFabian Stelzer, Dec 8, 2021
  37. 5/8 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Dec 8, 2021
  38. 6/8 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Dec 8, 2021
  39. 7/8 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Dec 8, 2021
  40. 8/8 t/fmt-merge-msg: make gpg/ssh tests more specificFabian Stelzer, Dec 8, 2021
  41. Junio C HamanoDec 8, 2021
  42. Fabian StelzerDec 9, 2021
  43. 0/9 ssh signing: verify key lifetimeFabian Stelzer, Dec 9, 2021
  44. 2/9 t/fmt-merge-msg: make gpgssh tests more specificFabian Stelzer, Dec 9, 2021
  45. 1/9 t/fmt-merge-msg: do not redirect stderrFabian Stelzer, Dec 9, 2021
  46. 3/9 ssh signing: use sigc struct to pass payloadFabian Stelzer, Dec 9, 2021
  47. 4/9 ssh signing: add key lifetime test prereqsFabian Stelzer, Dec 9, 2021
  48. 5/9 ssh signing: make verify-commit consider key lifetimeFabian Stelzer, Dec 9, 2021
  49. 6/9 ssh signing: make git log verify key lifetimeFabian Stelzer, Dec 9, 2021
  50. 7/9 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Dec 9, 2021
  51. 8/9 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Dec 9, 2021
  52. 9/9 ssh signing: verify ssh-keygen in test prereqFabian Stelzer, Dec 9, 2021
  53. 6/6 ssh signing: make fmt-merge-msg consider key lifetimeFabian Stelzer, Oct 27, 2021
  54. 4/6 ssh signing: make git log verify key lifetimeFabian Stelzer, Oct 27, 2021
  55. 5/6 ssh signing: make verify-tag consider key lifetimeFabian Stelzer, Oct 27, 2021
  56. Adam DinwoodieNov 3, 2021
  57. Fabian StelzerNov 3, 2021
  58. Adam DinwoodieNov 4, 2021
  59. Fabian StelzerNov 4, 2021
  60. Adam DinwoodieNov 4, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.