git/list[1] front-page[2] threads[3] people[4] search[5] about
 

gpg.ssh.defaultKeyCommand docs bug?

From
MSmatthew sporleder <msporleder@gmail.com>
Date
Oct 6, 2023, 17:14 UTC
Message-ID
<CAHKF-AvUxH1Ar3Xijjb4_8N+_kssPHZVHqQSAE9kDGRfTYHyxw@mail.gmail.com>
https://git-scm.com/docs/git-config#Documentation/git-config.txt-gpgsshdefaultKeyCommand

This command that will be run when user.signingkey is not set and a ssh signature is requested. On successful exit a valid ssh public key prefixed with key:: is expected in the first line of its output. This allows for a script doing a dynamic lookup of the correct public key when it is impractical to statically configure user.signingKey. For example when keys or SSH Certificates are rotated frequently or selection of the right key depends on external factors unknown to git.

---

The command does not actually work (for me, git version 2.42.0) with key:: prefixed.

It only works if I cat the public key as-is.

I only figured this out because the docs previously said it took the format of ssh-add -L, which also doesn't not contain key::.

I am using this script for my "dynamic" key discovery: #!/bin/sh f=$(ssh -G $(git remote get-url $(git remote|head -1)|awk -F':' '{ print $1 }') |grep -E '^identityfile'|sed 's#^identityfile ##g') cat $(eval realpath ${f}.pub)

Thanks, Matt

Next: Jeff King
Message 1 of 4 in “gpg.ssh.defaultKeyCommand docs bug?”
  1. matthew sporlederOct 6, 2023
  2. Jeff KingOct 9, 2023
  3. matthew sporlederOct 11, 2023
  4. Jeff KingOct 11, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.