git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: gpg-ssh signing with AgentForwarding

From
YBYarden Bar <ayash.jorden@gmail.com>
Date
Nov 14, 2024, 08:57 UTC
Message-ID
<CAJPGt+WwMWApt5o8E1nQGZnADbfjEkVmazUmxJ83Au6QPJ8Jdg@mail.gmail.com>
In-Reply-To
<ZyybBPigKZ_MlnU6@tapette.crustytoothpaste.net>

Hi all, A colleague of mine was able to figure it out. https://github.com/maxgoedjen/secretive/issues/405#issuecomment-2475175801 Hope it will help/serve the community

Jordan

On Thu, Nov 7, 2024 at 2:48 AM brian m. carlson <sandals@crustytoothpaste.net> wrote:

Show 40 quoted lines
>
> On 2024-11-07 at 04:16:34, Yarden Bar wrote:
> > Hello Git community,
> > Not sure what search terms I haven't used, but I'll try to describe the use-case
> >
> > On my local machine I have a SSH key, and I use AgentForwarding when I
> > go out and about to other hosts (dev machines)
> > The usual workflow of using the forwarded socket works for pull and push.
> >
> > Where it gets pitch-dark is when I try to use my ssh key to sign git commits.
> > Following is my git config on the remote host:
> > =====================
> > [user]
> >     name = John Doe
> >     email = jdoe@jdoe.com
> > # on my local machine(gpg-ssh signing works): signingkey =
> > /Users/jdoe/.ssh/id_ecdsa.pub
> >     signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to
> > the public key from Secretive, or just omit it?
>
> I think you want something like this:
>
>   [user]
>       signingkey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl"
>
> You should use your own key; that's just an example.  Note that you want
> the public key (that is, what's in `id_ecdsa.pub`, not `id_ecdsa`).
>
> Once you have the key in the config file like that, with the "key::"
> prefix, Git will pull from the agent if necessary.  I do that for
> signing commits using GitHub Codespaces, where it's easier to forward
> an SSH agent to the remote system than with GnuPG.
>
> This is documented in the `user.signingKey` entry in `git config
> --help`, but if there's something there that's unclear or you think the
> text could be improved, please say something, and we'll try to get it
> fixed.
> --
> brian m. carlson (they/them or he/him)
> Toronto, Ontario, CA
Previous: brian m. carlson
Message 4 of 4 in “gpg-ssh signing with AgentForwarding”
  1. Yarden BarNov 7, 2024
  2. Fabian StelzerNov 7, 2024
  3. brian m. carlsonNov 7, 2024
  4. Yarden BarNov 14, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.