Re: [PATCH v6 0/9] ssh signing: Add commit & tag signing/verification via SSH keys using ssh-keygen
- From
Bagas Sanjaya <bagasdotme@gmail.com>
- Date
- Jul 29, 2021, 08:19 UTC
- Message-ID
- <6b244afb-e4bb-c613-142a-4baba1149de3@gmail.com>
- In-Reply-To
- <pull.1041.v6.git.git.1627501009.gitgitgadget@gmail.com>
On 29/07/21 02.36, Fabian Stelzer via GitGitGadget wrote:
Show 9 quoted lines
> openssh 8.7 will add valid-after, valid-before options to the allowed keys > keyring. This allows us to pass the commit timestamp to the verification > call and make key rollover possible and still be able to verify older > commits. Set valid-after=NOW when adding your key to the keyring and set > valid-before to make it fail if used after a certain date. Software like > gitolite/github or corporate automation can do this automatically when ssh > push keys are addded / removed I will add this feature in a follow up patch > afterwards. >
I read above as "set valid-before=<some date> and valid-after=<now> to limit key validity for several days from now". Is it right?
-- An old man doll... just what I always wanted! - Clara