git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] ssh signing: support non ssh-* keytypes

From
Junio C Hamano <gitster@pobox.com>
Date
Nov 18, 2021, 06:39 UTC
Message-ID
<xmqqh7caynlf.fsf@gitster.g>
In-Reply-To
<xmqq4k8a2m97.fsf@gitster.g>
Junio C Hamano <gitster@pobox.com> writes:
Show 33 quoted lines
> Fabian Stelzer <fs@gigacodes.de> writes:
>
>> +/* Determines wether key contains a literal ssh key or a path to a file */
>> +static int is_literal_ssh_key(const char *key) {
>> +	return (
>> +		starts_with(key, "ssh-") ||
>> +		starts_with(key, "ecdsa-") ||
>> +		starts_with(key, "sk-ssh-") ||
>> +		starts_with(key, "sk-ecdsa-")
>> +	);
>> +}
>
> A more forward looking thing you could do is to 
>
>  (1) grandfather the convention "any string that begins with 'ssh-'
>      is taken as a ssh literal key".
>
>  (2) refrain from spreading such an unstructured mess by picking a
>      reserved prefix, say "ssh-key::" and have all other kinds of
>      ssh keys use the convention.
>
> making the above function look more like
>
>     static int is_literal_ssh_key(const char *string, const char **key)
>     {
> 	if (skip_prefix(string, "ssh-key::", key)
> 	    return 1;
> 	if (starts_with(string, "ssh-")) {
> 	    key = string;
> 	    return 1;
> 	}
> 	return 0;
>     }

Given that this ONLY gets called from ssh codepath, I think the special prefix can just be "key::", and when a new crypto suite is introduced to sit next to GPG and SSH, presumably the code structure to support it will be similar to that of ssh's, and it can also use "key::" prefix for their literal keys. That design may be cleaner.

Thanks.
Previous: Junio C HamanoNext: Fabian Stelzer
Message 4 of 12 in “ssh signing: support non ssh-* keytypes”
  1. ssh signing: support non ssh-* keytypesFabian Stelzer, Nov 17, 2021
  2. Taylor BlauNov 17, 2021
  3. Junio C HamanoNov 18, 2021
  4. Junio C HamanoNov 18, 2021
  5. Fabian StelzerNov 18, 2021
  6. 1/2 ssh signing: support non ssh-* keytypesFabian Stelzer, Nov 18, 2021
  7. 2/2 ssh signing: make sign/amend test more resilientFabian Stelzer, Nov 18, 2021
  8. Eric SunshineNov 18, 2021
  9. Fabian StelzerNov 19, 2021
  10. 0/2 ssh signing: support non ssh-* keytypesFabian Stelzer, Nov 19, 2021
  11. 1/2 ssh signing: support non ssh-* keytypesFabian Stelzer, Nov 19, 2021
  12. 2/2 ssh signing: make sign/amend test more resilientFabian Stelzer, Nov 19, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.