git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] ssh signing: Support ECDSA as literal SSH keys

From
Fabian Stelzer <fs@gigacodes.de>
Date
May 31, 2022, 14:47 UTC
Message-ID
<20220531144703.jbawf3tkypt7se2i@fs>
In-Reply-To
<CA+vJLfu1WyqP4V44iyZj+Fyr8O7JSB8tSJfOmS1SeSZ65fXh0w@mail.gmail.com>
On 31.05.2022 09:28, Andy Lindeman wrote:
Show 33 quoted lines
>On Tue, May 31, 2022 at 3:34 AM Fabian Stelzer <fs@gigacodes.de> wrote:
>> On 30.05.2022 17:45, Andy Lindeman via GitGitGadget wrote:
>> >From: Andy Lindeman <andy@lindeman.io>
>> >
>> >Keys generated using `ssh-keygen -t ecdsa` or similar are being rejected
>> >as literal SSH keys because the prefix is `ecdsa-sha2-nistp256`,
>> >`ecdsa-sha2-nistp384` or `ecdsa-sha2-nistp521`.
>> >
>> >This was acknowledged as an issue [1] in the past, but hasn't yet been
>> >fixed.
>>
>> Hi Andy,
>> thanks for your report. We have decided in the past to not explicitly cater
>> to every key prefix and instead use `key::` for literal keys.
>> See
>> https://git-scm.com/docs/git-config#Documentation/git-config.txt-usersigningKey
>>
>> `For backward compatibility, a raw key which begins with "ssh-", such as
>> "ssh-rsa XXXXXX identifier", is treated as "key::ssh-rsa XXXXXX identifier",
>> but this form is deprecated; use the key:: form instead.`
>
>Thanks for replying, Fabian.
>
>My main issue is that ecdsa-sha2-* keys currently seem incompatible
>with `gpg.ssh.defaultKeyCommand = "ssh-add -L"`
>
>The git-config documentation of `gpg.ssh.defaultKeyCommand` says:
>
>> To automatically use the first available key from your ssh-agent set this to "ssh-add -L".
>
>But this does not work with ecdsa keys because each line of the output
>of the command is checked against `is_literal_ssh_key`. Because of
>that check, keys that do not begin with `ssh-` are skipped.
True, this is a bug.
>
>I could certainly write my own shell script for `defaultKeyCommand`
>that did something like `ssh-add -L | sed 's/^/key::/'` but it's a bit
>awkward.
I think this is at least a valid workaround for now.
Show 12 quoted lines
>
>The code that runs `defaultKeyCommand` states:
>
>> /*
>> * We only use `is_literal_ssh_key` here to check validity
>> * The prefix will be stripped when the key is used.
>> */
>
>but this is clearly not true because it is rejecting valid SSH keys.
>
>Do you have thoughts on how to improve `gpg.ssh.defaultKeyCommand` for
>keys whose prefix is not `ssh-` ?

The problem is that we do not want to maintain all ssh keytypes in the git code. Thats why the `key::` was added. I'll have to think what we could do besides just skipping the check completely and just assuming the defaultKeyCommand will return a valid key. ssh-add -L is not necessarily defined as having a parsable output and any additional messages it might print (or some pkcs11 provider) would at least be skipped with the ssh- prefix check.

Previous: Andy LindemanNext: Junio C Hamano
Message 4 of 9 in “ssh signing: Support ECDSA as literal SSH keys”
  1. ssh signing: Support ECDSA as literal SSH keysAndy Lindeman via GitGitGadget, May 30, 2022
  2. Fabian StelzerMay 31, 2022
  3. Andy LindemanMay 31, 2022
  4. Fabian StelzerMay 31, 2022
  5. Junio C HamanoJun 1, 2022
  6. Fabian StelzerJun 7, 2022
  7. Junio C HamanoJun 7, 2022
  8. gpg docs: explain better use of ssh.defaultKeyCommandFabian Stelzer, Jun 8, 2022
  9. Andy LindemanJun 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.