git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] gpg docs: explain better use of ssh.defaultKeyCommand

From
Fabian Stelzer <fs@gigacodes.de>
Date
Jun 8, 2022, 15:24 UTC
Message-ID
<20220608152437.126276-1-fs@gigacodes.de>
In-Reply-To
<xmqqa6awvp60.fsf@gitster.g>

Using `ssh-add -L` for gpg.ssh.defaultKeyCommand is not a good recommendation. It might switch keys depending on the order of known keys and it only supports ssh-* and no ecdsa or other keys. Clarify that we expect a literal key prefixed by `key::`, give valid example use cases and refer to `user.signingKey` as the preferred option.

Signed-off-by: Fabian Stelzer <fs@gigacodes.de>
---
 Documentation/config/gpg.txt | 9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/Documentation/config/gpg.txt b/Documentation/config/gpg.txt
index 86892ada77..86f6308c4c 100644
--- a/Documentation/config/gpg.txt
+++ b/Documentation/config/gpg.txt
@@ -36,9 +36,12 @@ gpg.minTrustLevel::
 
 gpg.ssh.defaultKeyCommand::
 	This command that will be run when user.signingkey is not set and a ssh
-	signature is requested. On successful exit a valid ssh public key is
-	expected in the first line of its output. To automatically use the first
-	available key from your ssh-agent set this to "ssh-add -L".
+	signature is requested. On successful exit a valid ssh public key
+	prefixed with `key::` is expected in the first line of its output.
+	This allows for a script doing a dynamic lookup of the correct public
+	key when it is impractical to statically configure `user.signingKey`.
+	For example when keys or SSH Certificates are rotated frequently or
+	selection of the right key depends on external factors unknown to git.
 
 gpg.ssh.allowedSignersFile::
 	A file containing ssh public keys which you are willing to trust.
-- 
2.35.3
Previous: Junio C HamanoNext: Andy Lindeman
Message 8 of 9 in “ssh signing: Support ECDSA as literal SSH keys”
  1. ssh signing: Support ECDSA as literal SSH keysAndy Lindeman via GitGitGadget, May 30, 2022
  2. Fabian StelzerMay 31, 2022
  3. Andy LindemanMay 31, 2022
  4. Fabian StelzerMay 31, 2022
  5. Junio C HamanoJun 1, 2022
  6. Fabian StelzerJun 7, 2022
  7. Junio C HamanoJun 7, 2022
  8. gpg docs: explain better use of ssh.defaultKeyCommandFabian Stelzer, Jun 8, 2022
  9. Andy LindemanJun 13, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.