git/list[1] front-page[2] threads[3] people[4] search[5] about
 

ssh signing: valid-before is checked at the signer's own date, and a missing revocationFile fails open

From
CLChristian Noé Ramos López <chris@nortesoftware.dev>
Date
Oct 8, 2026, 06:56 UTC
Message-ID
<CAHGSfbZ_Q8Ujt3om0POapkjWZed1pZVUrB-mV-e+UjmPgCNvWQ@mail.gmail.com>

Two things that, together, mean an SSH signing key cannot be reliably stopped from being trusted. git 2.47.3, OpenSSH 10.0p2, Debian 13; source read at v2.47.3 and at master (c46c1e37724f).

1. valid-before is checked at a date the signer writes.

SSH signatures carry no time of their own, so git passes -Overify-time from the committer or tagger line (gpg-interface.c, parse_payload_metadata). alice's key is in the allowed signers file with valid-before="20260101":

    ssh-old        %G?=G 2025-06-01 12:00:00 +0000 verify-commit=0 merge=0
    ssh-backdated  %G?=G 2025-06-01 12:00:00 +0000 verify-commit=0 merge=0
    ssh-honest     %G?=U 2026-10-08 02:15:15 -0400 verify-commit=1 merge=128

ssh-backdated was signed today, with only the committer and author dates set to 2025-06-01. Nothing distinguishes it from ssh-old except when it was made, which only its author knows. ssh-honest, signed and dated today, is refused: "key has expired: verify time ... > valid-before 2026-01-01T00:00:00".

The GPG backend refuses both:
    gpg-old        %G?=Y verify-commit=1 merge=128
    gpg-backdated  %G?=Y verify-commit=1 merge=128

The documentation for gpg.ssh.allowedSignersFile says "Git will mark signatures as valid if the signing key was valid at the time of the signature's creation", which is the intent, but does not say the time comes from the commit. So valid-before rotates a key; it does not retire one.

2. A configured revocation file that does not exist fails open.

gpg-interface.c:568-574 at v2.47.3 (579-586 at master): if the revocation file exists, pass -r; otherwise warn and verify without it. The same file, present and listing alice's key, refuses:

    S2-revoked       %G?=B verify-commit=1 merged=no
    S3-revfile-gone  %G?=G verify-commit=0 merged=yes
                     warning: ssh signing revocation file configured
but not found

S3 merged under `git merge --ff-only --verify-signatures`. An unreadable file and a directory both fail closed:

    S4-revfile-0000  %G?=B verify-commit=1 merged=no
    S6-revfile-dir   %G?=B verify-commit=1 merged=no

ssh-keygen, given the same missing path, refuses: exit 255, "Could not verify signature". git avoids that by not passing -r. OpenSSH's RevokedKeys says, in sshd_config(5), "Note that if this file is not readable, then public key authentication will be refused for all users."

No test in git exercises gpg.ssh.revocationFile; it appears only in Documentation/config/gpg.adoc and gpg-interface.c.

Controls for both runs, fixed beforehand: a good signature gives G and merges; an unsigned commit gives N and is refused; the revocation file present and listing the key gives B and is refused; a commit with its message changed and the signature kept gives B and is refused.

Together: the two ways to stop trusting an SSH signing key are
valid-before, which the signer can date around, and revocationFile,
which does nothing if its path is wrong. Either would be enough on its
own if it held.

What I would ask for: refuse when the revocation file is configured and missing, as ssh-keygen and sshd do, or say in the documentation that it is ignored; and say, under valid-before, where the time compared against it comes from.

On prior art: the ssh signing series (Fabian Stelzer, 2021) carried the warning from before v4, and the review raised the config name's case, not what a missing file should do. The key-lifetime series (RFC 2021-10-15 to v6 2021-12-09) passes the commit date to the check, and the replies are about style. The N for an unconfigured allowed signers file is already on the list (Grayson Tinker, 2026-06-25) and is not part of this.

Christian Ramos Norte Software chris@nortesoftware.dev

Next: Phillip Wood
Message 1 of 5 in “ssh signing: valid-before is checked at the signer's own date, and a missing revocationFile fails open”
  1. Christian Noé Ramos LópezOct 8, 2026
  2. Phillip WoodOct 8, 2026
  3. Patrick SteinhardtOct 9, 2026
  4. Phillip WoodOct 9, 2026
  5. Phillip WoodOct 9, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.