# Unable to use security key to commit signing using SSH keypair

3 messages from 2022-06-28 to 2022-06-28. Participants: Marcos Alano, Fabian Stelzer.
Thread: https://gitlist.dev/t/58075

## Marcos Alano, 2022-06-28 00:09

Subject: Unable to use security key to commit signing using SSH keypair
Message-ID: <97adcd90-b4d3-1114-205b-3445dd48b497@gmail.com>
URL: https://gitlist.dev/e/97adcd90-b4d3-1114-205b-3445dd48b497%40gmail.com

```
Hello fellows!

I'm able to sign commits using SSH keypair, but the keypair must be 
located in a file. If I try to use a SSH keypair in a security key (like 
an YubiKey) I get an error. I used this commands to do the test:
ˋˋˋ
ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk
git config --global gpg.format ssh
git config --global user.signingkey "$(cat ~/.ssh/id_ed25519_sk.pub)"
git commit -S --allow-empty --message="Testing"
ˋˋˋ

Bnd I get this error:
ˋˋˋ
error: Couldn't load public key sk-ssh-ed25519@openssh.com <my key id>: 
No such file or directory?

fatal: failed to write commit object
ˋˋˋ
I did the same thing with a plain ed25519 keypair and worked.

Am I doing anything wrong or security keys aren't supported yet?

Thank you for any help,
-- 
Marcos Alano

```

## Fabian Stelzer, 2022-06-28 16:23

Subject: Re: Unable to use security key to commit signing using SSH keypair
Message-ID: <20220628162342.ootjobbjtxg7b7ay@fs>
URL: https://gitlist.dev/e/20220628162342.ootjobbjtxg7b7ay%40fs
In-Reply-To: <97adcd90-b4d3-1114-205b-3445dd48b497@gmail.com>

```
On 27.06.2022 21:09, Marcos Alano wrote:
>Hello fellows!
>
>I'm able to sign commits using SSH keypair, but the keypair must be 
>located in a file. If I try to use a SSH keypair in a security key 
>(like an YubiKey) I get an error. I used this commands to do the test:
>ˋˋˋ
>ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk
>git config --global gpg.format ssh
>git config --global user.signingkey "$(cat ~/.ssh/id_ed25519_sk.pub)"

Did you try just putting the public keys path into user.signingkey?
Literal keys would need to be prefixed with `key::`

git config --global user.signingkey ~/.ssh/id_ed25519_sk.pub
should be just fine.

Also, the private key needs to be available in your ssh agent. If in doubt 
you can check with a `ssh-add -L`.

>git commit -S --allow-empty --message="Testing"
>ˋˋˋ
>
>Bnd I get this error:
>ˋˋˋ
>error: Couldn't load public key sk-ssh-ed25519@openssh.com <my key 
>id>: No such file or directory?
>
>fatal: failed to write commit object
>ˋˋˋ
>I did the same thing with a plain ed25519 keypair and worked.
>
>Am I doing anything wrong or security keys aren't supported yet?
>
>Thank you for any help,
>-- 
>Marcos Alano

```

## Marcos Alano, 2022-06-28 16:43

Subject: Re: Unable to use security key to commit signing using SSH keypair
Message-ID: <671b375c-66e5-0164-3625-4ccfa57ece95@gmail.com>
URL: https://gitlist.dev/e/671b375c-66e5-0164-3625-4ccfa57ece95%40gmail.com
In-Reply-To: <20220628162342.ootjobbjtxg7b7ay@fs>

```
On 28/06/2022 13:23, Fabian Stelzer wrote:
> On 27.06.2022 21:09, Marcos Alano wrote:
>> Hello fellows!
>>
>> I'm able to sign commits using SSH keypair, but the keypair must be 
>> located in a file. If I try to use a SSH keypair in a security key 
>> (like an YubiKey) I get an error. I used this commands to do the test:
>> ˋˋˋ
>> ssh-keygen -t ed25519-sk -f ~/.ssh/id_ed25519_sk
>> git config --global gpg.format ssh
>> git config --global user.signingkey "$(cat ~/.ssh/id_ed25519_sk.pub)"
> 
> Did you try just putting the public keys path into user.signingkey?
> Literal keys would need to be prefixed with `key::`
> 
Thank you, worked like a charm. Every documentation I read told me to 
use the plain public key, without the path or the prefix you indicated. 
And worked well with a regular keypair.

Using the path and prefixing the public key worked.

You have my gratitude. :)

Stay well,
> git config --global user.signingkey ~/.ssh/id_ed25519_sk.pub
> should be just fine.
> 
> Also, the private key needs to be available in your ssh agent. If in 
> doubt you can check with a `ssh-add -L`.
> 
>> git commit -S --allow-empty --message="Testing"
>> ˋˋˋ
>>
>> Bnd I get this error:
>> ˋˋˋ
>> error: Couldn't load public key sk-ssh-ed25519@openssh.com <my key 
>> id>: No such file or directory?
>>
>> fatal: failed to write commit object
>> ˋˋˋ
>> I did the same thing with a plain ed25519 keypair and worked.
>>
>> Am I doing anything wrong or security keys aren't supported yet?
>>
>> Thank you for any help,
>> -- 
>> Marcos Alano

-- 
Marcos Alano


```
