git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Using principal wildcards in gpg.ssh.allowedSignersFile

From
MMMatthias Maier <tamiko-gitvger@43-1.org>
Date
Dec 17, 2021, 16:41 UTC
Message-ID
<87czlv5glg.fsf@43-1.org>
In-Reply-To
<20211217094235.i2fwildp7rcjcgtz@fs>
Hi Fabian,
Thanks for doing the bug report to openssh!
On Fri, Dec 17, 2021, at 03:42 CST, Fabian Stelzer <fs@gigacodes.de> wrote:
> [...]
Show 14 quoted lines
>>  $ ssh-keygen -Y find-principals -f allowed_signers -n file -s test.txt.sig
>>  tamiko@43-1.org
>
> Are you sure the allowed_signers file was exactly what you generated
> before for this command? If I follow your steps this will not produce
> a principal for me with neither openssh-8.8.1, nor master. Can you run
> this with `-vvv` which will show a bit more ssh internal output?
> In the openssh code for find-principals wildcard principals are
> filtered for CA certs. I'm not sure why and have asked them about it.
>
> By the way, find-principals will not consider the namespace parameter.
> This has another bug in the current master producing a segfault for
> which I've already sent a patch. But this should be unrelated to your
> issue.

You're absolutely right - I did confuse myself. The find-principals call does not work:

    % ssh-keygen -vvv -Y find-principals -f allowed_signers -n file -s test.txt.sig
    debug3: allowed_signers:1: options cert-authority,namespaces="file,git"
    debug1: allowed_signers:1: principal "*@43-1.org" not authorized: contains wildcards
    allowed_signers:1: no valid principals found
    debug1: allowed_signers:1: cert_filter_principals: invalid certificate
    No principal matched.

I agree. It is interesting that they explicitly filter wildcards for the find-principals call. Let's see what openssh upstream has to say.

> [...]
>
> Just FYI: if you add GIT_TRACE=1 to the git commands you can see the
> executed ssh-keygen commands, which can help to see whats going on.
Ah, that's neat!

Best, Matthias

Previous: Fabian StelzerNext: Fabian Stelzer
Message 3 of 5 in “Using principal wildcards in gpg.ssh.allowedSignersFile”
  1. Matthias MaierDec 17, 2021
  2. Fabian StelzerDec 17, 2021
  3. Matthias MaierDec 17, 2021
  4. Fabian StelzerFeb 3, 2022
  5. Junio C HamanoFeb 3, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.