git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Error / feature-request: Signing git commits with SSH hardware key

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Oct 11, 2022, 20:41 UTC
Message-ID
<Y0XVCDu9o3xDnt81@tapette.crustytoothpaste.net>
In-Reply-To
<875ygqw7p8.fsf@ngraves.fr>
On 2022-10-11 at 18:12:19, Nicolas Graves wrote:
> 
> Hi!
Hey,
> I noticed git commit signing works well with ssh-ed25519 keys, but does
> fail with sk-ssh-ed25519@openssh.com SSH hardware keys (with can be
> used to clone / post to github for instance).

I was surprised to hear that, so I just tested on my Debian amd64/sid system, and I was able to sign and verify using an sk-ssh-ed25519@openssh.com SSH key using my YubiKey 5C. I do believe it does work, although when the signature occurs, there's no notice that it's waiting for user interaction, so you just have to look at the lights to determine that the touch is needed.

Could you maybe mention what version of OpenSSH you're using and on what platform? I used 9.0p1, and as I mentioned, it's Linux. The output looks like so:

  $ git verify-commit --raw HEAD
  Good "git" signature for sandals@crustytoothpaste.net with ED25519-SK key SHA256:PNxAWB7cxxxrCTbgsdoDq71o3rCm9O7Er4q+0YrEAdM

Specifically, what error message or other indications of failure do you see when you try to sign?

Show 5 quoted lines
> I also noticed a similar error in a previous mail from Cuckoo Aidan
> <aidancuckoo@gmail.com>, but he doesn't say which type of key he
> used. In any case, would that be possible to include the info about
> which type of keys cannot be used to commit in the github guide
> https://docs.github.com/en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key#telling-git-about-your-ssh-key) ?

We don't control the GitHub documentation, since we're independent of GitHub. If there's incorrect information, you'd need to contact GitHub. However, as I mentioned above, I do believe this works at least in some cases.

-- 
brian m. carlson (he/him or they/them)
Toronto, Ontario, CA
Previous: Nicolas GravesNext: Nicolas Graves
Message 2 of 7 in “Error / feature-request: Signing git commits with SSH hardware key”
  1. Nicolas GravesOct 11, 2022
  2. brian m. carlsonOct 11, 2022
  3. Nicolas GravesOct 11, 2022
  4. Nicolas GravesOct 11, 2022
  5. Nicolas GravesOct 12, 2022
  6. Fabian StelzerOct 12, 2022
  7. Nicolas GravesOct 12, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.