git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] ssh signing: Support ECDSA as literal SSH keys

From
Fabian Stelzer <fs@gigacodes.de>
Date
May 31, 2022, 07:34 UTC
Message-ID
<20220531073445.iuovy634ufp5xims@fs>
In-Reply-To
<pull.1272.git.git.1653932705097.gitgitgadget@gmail.com>
On 30.05.2022 17:45, Andy Lindeman via GitGitGadget wrote:
Show 8 quoted lines
>From: Andy Lindeman <andy@lindeman.io>
>
>Keys generated using `ssh-keygen -t ecdsa` or similar are being rejected
>as literal SSH keys because the prefix is `ecdsa-sha2-nistp256`,
>`ecdsa-sha2-nistp384` or `ecdsa-sha2-nistp521`.
>
>This was acknowledged as an issue [1] in the past, but hasn't yet been
>fixed.

Hi Andy, thanks for your report. We have decided in the past to not explicitly cater to every key prefix and instead use `key::` for literal keys. See https://git-scm.com/docs/git-config#Documentation/git-config.txt-usersigningKey

`For backward compatibility, a raw key which begins with "ssh-", such as "ssh-rsa XXXXXX identifier", is treated as "key::ssh-rsa XXXXXX identifier", but this form is deprecated; use the key:: form instead.`

Show 40 quoted lines
>
>[1]: https://github.com/git/git/pull/1041#issuecomment-971425601
>
>Signed-off-by: Andy Lindeman <andy@lindeman.io>
>---
>    ssh signing: Support ECDSA as literal SSH keys
>
>    Keys generated using ssh-keygen -t ecdsa or similar will currently be
>    rejected as literal SSH keys because the prefix is ecdsa-sha2-nistp256,
>    ecdsa-sha2-nistp384 or ecdsa-sha2-nistp521.
>
>    This was acknowledged as an issue in the past, but hasn't yet been
>    fixed.
>
>    https://github.com/git/git/pull/1041#issuecomment-971425601
>
>Published-As: https://github.com/gitgitgadget/git/releases/tag/pr-git-1272%2Falindeman%2Fecdsa-sha2-keys-v1
>Fetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-git-1272/alindeman/ecdsa-sha2-keys-v1
>Pull-Request: https://github.com/git/git/pull/1272
>
> gpg-interface.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
>diff --git a/gpg-interface.c b/gpg-interface.c
>index 280f1fa1a58..086bd03b51d 100644
>--- a/gpg-interface.c
>+++ b/gpg-interface.c
>@@ -779,7 +779,7 @@ static int is_literal_ssh_key(const char *string, const char **key)
> {
> 	if (skip_prefix(string, "key::", key))
> 		return 1;
>-	if (starts_with(string, "ssh-")) {
>+	if (starts_with(string, "ssh-") || starts_with(string, "ecdsa-sha2-")) {
> 		*key = string;
> 		return 1;
> 	}
>
>base-commit: 8ddf593a250e07d388059f7e3f471078e1d2ed5c
>-- 
>gitgitgadget
Previous: Andy Lindeman via GitGitGadgetNext: Andy Lindeman
Message 2 of 9 in “ssh signing: Support ECDSA as literal SSH keys”
  1. ssh signing: Support ECDSA as literal SSH keysAndy Lindeman via GitGitGadget, May 30, 2022
  2. Fabian StelzerMay 31, 2022
  3. Andy LindemanMay 31, 2022
  4. Fabian StelzerMay 31, 2022
  5. Junio C HamanoJun 1, 2022
  6. Fabian StelzerJun 7, 2022
  7. Junio C HamanoJun 7, 2022
  8. gpg docs: explain better use of ssh.defaultKeyCommandFabian Stelzer, Jun 8, 2022
  9. Andy LindemanJun 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.