git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Using principal wildcards in gpg.ssh.allowedSignersFile

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 3, 2022, 18:43 UTC
Message-ID
<xmqqfsozvlhu.fsf@gitster.g>
In-Reply-To
<20220203124104.77ioij3jqqqyoc54@fs>
Fabian Stelzer <fs@gigacodes.de> writes:
Show 10 quoted lines
>> Thanks for your report. I tested the described behaviour and I think
>> this is a bug in openssh. find-principals will never match on a CA 
>> cert with wildcard principals whereas wildcards for non-CA keys work
>> just fine. I've emailed the openssh maintainer about it and will 
>>prepare a patch.
>
> Just for reference to the git list:
> This issue was fixed with
> https://github.com/openssh/openssh-portable/commit/15b7199a1fd37eff4c695e09d573f3db9f4274b7
> which should be in the next openssh release.
Thanks for a heads-up.
Previous: Fabian Stelzer
Message 5 of 5 in “Using principal wildcards in gpg.ssh.allowedSignersFile”
  1. Matthias MaierDec 17, 2021
  2. Fabian StelzerDec 17, 2021
  3. Matthias MaierDec 17, 2021
  4. Fabian StelzerFeb 3, 2022
  5. Junio C HamanoFeb 3, 2022

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.