# Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent

3 messages from 2024-09-13 to 2024-09-14. Participants: Justin Su, Phillip Wood.
Thread: https://gitlist.dev/t/62105

## Justin Su, 2024-09-13 09:58

Subject: Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent
Message-ID: <CAB=S_8JhN=WSuYRMWbGz7gZMRX9dSb3k8rJZ7zrxkbHKOqfzww@mail.gmail.com>
URL: https://gitlist.dev/e/CAB%3DS_8JhN%3DWSuYRMWbGz7gZMRX9dSb3k8rJZ7zrxkbHKOqfzww%40mail.gmail.com

```
I use Secretive (https://github.com/maxgoedjen/secretive) to store my
SSH keys on macOS. I've configured my ssh_config to use it as the
IdentityAgent, and Git can push and pull just fine.

However, it seems that Git ignores IdentityAgent when signing commits,
resulting in the following error message:

error: No private key found for public key "foo.pub"?
fatal: failed to write commit object

I've worked around this by setting SSH_AUTH_SOCK, but this doesn't
feel correct to me. Is this intended behaviour?

Thanks,
Justin

```

## Phillip Wood, 2024-09-13 15:05

Subject: Re: Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent
Message-ID: <a25f71ad-093f-4e8d-97ef-503bfb9926d2@gmail.com>
URL: https://gitlist.dev/e/a25f71ad-093f-4e8d-97ef-503bfb9926d2%40gmail.com
In-Reply-To: <CAB=S_8JhN=WSuYRMWbGz7gZMRX9dSb3k8rJZ7zrxkbHKOqfzww@mail.gmail.com>

```
Hi Justin

On 13/09/2024 10:58, Justin Su wrote:
> I use Secretive (https://github.com/maxgoedjen/secretive) to store my
> SSH keys on macOS. I've configured my ssh_config to use it as the
> IdentityAgent, and Git can push and pull just fine.
> 
> However, it seems that Git ignores IdentityAgent when signing commits,
> resulting in the following error message:

Git just runs "ssh -Y". I can reproduce this on linux - I suspect the 
problem is that ssh does not read the IdentityAgent config when signing 
even if it is outside a Host/Match in the config file.

Best Wishes

Phillip

> error: No private key found for public key "foo.pub"?
> fatal: failed to write commit object
> 
> I've worked around this by setting SSH_AUTH_SOCK, but this doesn't
> feel correct to me. Is this intended behaviour?
> 
> Thanks,
> Justin
> 

```

## Justin Su, 2024-09-14 16:08

Subject: Re: Commit signing with SSH key uses SSH_AUTH_SOCK but ignores IdentityAgent
Message-ID: <CAB=S_8+SAYVBNPByMrgmPQtA9JKmKt+kmeRBB=9=bSR2LLiMkw@mail.gmail.com>
URL: https://gitlist.dev/e/CAB%3DS_8%2BSAYVBNPByMrgmPQtA9JKmKt%2BkmeRBB%3D9%3DbSR2LLiMkw%40mail.gmail.com
In-Reply-To: <a25f71ad-093f-4e8d-97ef-503bfb9926d2@gmail.com>

```
On Fri, Sep 13, 2024 at 11:05 AM Phillip Wood <phillip.wood123@gmail.com> wrote:
>
> Hi Justin
>
> On 13/09/2024 10:58, Justin Su wrote:
> > I use Secretive (https://github.com/maxgoedjen/secretive) to store my
> > SSH keys on macOS. I've configured my ssh_config to use it as the
> > IdentityAgent, and Git can push and pull just fine.
> >
> > However, it seems that Git ignores IdentityAgent when signing commits,
> > resulting in the following error message:
>
> Git just runs "ssh -Y". I can reproduce this on linux - I suspect the
> problem is that ssh does not read the IdentityAgent config when signing
> even if it is outside a Host/Match in the config file.

Agreed, this seems like a ssh-keygen limitation. I reproduced this
directly with ssh-keygen on macOS.

According to its man page, if you pass a public key for the `-f`
option, then the private half needs to be available via ssh-agent. The
man page doesn't mention SSH_AUTH_SOCK either, but I guess it's the
best solution for my use case.

> Best Wishes
>
> Phillip
>
> > error: No private key found for public key "foo.pub"?
> > fatal: failed to write commit object
> >
> > I've worked around this by setting SSH_AUTH_SOCK, but this doesn't
> > feel correct to me. Is this intended behaviour?
> >
> > Thanks,
> > Justin
> >

```
