Re: [PATCH v6 0/9] ssh signing: Add commit & tag signing/verification via SSH keys using ssh-keygen
- From
Fabian Stelzer <fs@gigacodes.de>
- Date
- Jul 29, 2021, 11:03 UTC
- Message-ID
- <7689f8c6-0ac7-0121-4034-c8747edaad05@gigacodes.de>
- In-Reply-To
- <6b244afb-e4bb-c613-142a-4baba1149de3@gmail.com>
On 29.07.21 10:19, Bagas Sanjaya wrote:
Show 17 quoted lines
> On 29/07/21 02.36, Fabian Stelzer via GitGitGadget wrote: >> openssh 8.7 will add valid-after, valid-before options to the allowed >> keys >> keyring. This allows us to pass the commit timestamp to the verification >> call and make key rollover possible and still be able to verify older >> commits. Set valid-after=NOW when adding your key to the keyring and set >> valid-before to make it fail if used after a certain date. Software like >> gitolite/github or corporate automation can do this automatically when >> ssh >> push keys are addded / removed I will add this feature in a follow up >> patch >> afterwards. >> > > I read above as "set valid-before=<some date> and valid-after=<now> to > limit key validity for several days from now". Is it right? >
no. "NOW" is not meant literally but in the sense to add the current date when adding the key. I'll edit the description. But this feature in general will follow in a separate patchset with proper documentation anyway.