# gpg-ssh signing with AgentForwarding

4 messages from 2024-11-07 to 2024-11-14. Participants: Yarden Bar, Fabian Stelzer, brian m. carlson.
Thread: https://gitlist.dev/t/62463

## Yarden Bar, 2024-11-07 04:16

Subject: gpg-ssh signing with AgentForwarding
Message-ID: <CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com>
URL: https://gitlist.dev/e/CAJPGt%2BU1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA%40mail.gmail.com

```
Hello Git community,
Not sure what search terms I haven't used, but I'll try to describe the use-case

On my local machine I have a SSH key, and I use AgentForwarding when I
go out and about to other hosts (dev machines)
The usual workflow of using the forwarded socket works for pull and push.

Where it gets pitch-dark is when I try to use my ssh key to sign git commits.
Following is my git config on the remote host:
=====================
[user]
    name = John Doe
    email = jdoe@jdoe.com
# on my local machine(gpg-ssh signing works): signingkey =
/Users/jdoe/.ssh/id_ecdsa.pub
    signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to
the public key from Secretive, or just omit it?
[gpg]
    format = ssh
[commit]
    gpgsign = true
[gpg "ssh"]
    allowedSignersFile = /Users/jdoe/.gpg.ssh.allowedSignersFile #
contents is: "email1,email2 key-type public_key comment"
=====================

I've tried
1. `ssh-agent -a /path/to/ssh.sock` - errored with address already in use
2. signingkey set to a path on the remote host with my public key,
errored with "no private key found"

I sense that I should be able to employ `gpg.ssh.defaultKeyCommand` to
use the socket somehow, but I can't wrap my head around it or find
some docs/guidance.

Other (related) links
https://developer.1password.com/docs/ssh/git-commit-signing/ - I think
that 1Password invested the time to make it work
https://github.com/maxgoedjen/secretive/discussions/338#discussioncomment-11170722
- asked the same on Secretive repo, which is one way to store keys
https://github.com/maxgoedjen/secretive/issues/405#issuecomment-2460948732
- also here.

Thank you,
Jordan

```

## Fabian Stelzer, 2024-11-07 09:07

Subject: Re: gpg-ssh signing with AgentForwarding
Message-ID: <oeic2p6av3b65mibwmtmiiiciduufysqw4wekileu2tlch3ryx@uqtxefn2wuf5>
URL: https://gitlist.dev/e/oeic2p6av3b65mibwmtmiiiciduufysqw4wekileu2tlch3ryx%40uqtxefn2wuf5
In-Reply-To: <CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com>

```
On 06.11.2024 20:16, Yarden Bar wrote:
>Hello Git community,
>Not sure what search terms I haven't used, but I'll try to describe the use-case
>
>On my local machine I have a SSH key, and I use AgentForwarding when I
>go out and about to other hosts (dev machines)
>The usual workflow of using the forwarded socket works for pull and push.
>
>Where it gets pitch-dark is when I try to use my ssh key to sign git commits.
>Following is my git config on the remote host:

Hi Jordan,
the process on the remote host is pretty much identical to your local one as 
long as the AgentForwarding works. When pull/push work so should the 
signing.
One small caveat for older remote machines can be that you'll need a 
somewhat recent openssh version. Default redhat 7 or 8 for example will not 
work.
The ssh-keygen command needs the `-Y sign|verify` commands. If the remote is 
too old you can place a newer ssh-keygen there yourself and reference it in 
your git config via gpg.ssh.program

>=====================
>[user]
>    name = John Doe
>    email = jdoe@jdoe.com
># on my local machine(gpg-ssh signing works): signingkey =
>/Users/jdoe/.ssh/id_ecdsa.pub
>    signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to
>the public key from Secretive, or just omit it?

A path to your public key file or the literal key prefixed with key:: is 
fine.

>[gpg]
>    format = ssh
>[commit]
>    gpgsign = true
>[gpg "ssh"]
>    allowedSignersFile = /Users/jdoe/.gpg.ssh.allowedSignersFile #
>contents is: "email1,email2 key-type public_key comment"
>=====================
>
>I've tried
>1. `ssh-agent -a /path/to/ssh.sock` - errored with address already in use
>2. signingkey set to a path on the remote host with my public key,
>errored with "no private key found"
>
>I sense that I should be able to employ `gpg.ssh.defaultKeyCommand` to
>use the socket somehow, but I can't wrap my head around it or find
>some docs/guidance.

No need for defaultKeyCommand and no need to start another agent on the 
remote host.
If you get the "no private key found" error then the connection to the ssh 
agent does not work. (Maybe because you started another on the remote?)
You can test this easily by running "ssh-add -l" on the remote host which 
should print your public keys from the agent.

Kind regards,
Fabian

>
>Other (related) links
>https://developer.1password.com/docs/ssh/git-commit-signing/ - I think
>that 1Password invested the time to make it work
>https://github.com/maxgoedjen/secretive/discussions/338#discussioncomment-11170722
>- asked the same on Secretive repo, which is one way to store keys
>https://github.com/maxgoedjen/secretive/issues/405#issuecomment-2460948732
>- also here.
>
>Thank you,
>Jordan
>

```

## brian m. carlson, 2024-11-07 10:48

Subject: Re: gpg-ssh signing with AgentForwarding
Message-ID: <ZyybBPigKZ_MlnU6@tapette.crustytoothpaste.net>
URL: https://gitlist.dev/e/ZyybBPigKZ_MlnU6%40tapette.crustytoothpaste.net
In-Reply-To: <CAJPGt+U1icoNJHPtiFcidtwN6ts03jH9WpaGxDGoE5RBQSCCLA@mail.gmail.com>

```
On 2024-11-07 at 04:16:34, Yarden Bar wrote:
> Hello Git community,
> Not sure what search terms I haven't used, but I'll try to describe the use-case
> 
> On my local machine I have a SSH key, and I use AgentForwarding when I
> go out and about to other hosts (dev machines)
> The usual workflow of using the forwarded socket works for pull and push.
> 
> Where it gets pitch-dark is when I try to use my ssh key to sign git commits.
> Following is my git config on the remote host:
> =====================
> [user]
>     name = John Doe
>     email = jdoe@jdoe.com
> # on my local machine(gpg-ssh signing works): signingkey =
> /Users/jdoe/.ssh/id_ecdsa.pub
>     signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to
> the public key from Secretive, or just omit it?

I think you want something like this:

  [user]
      signingkey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl"

You should use your own key; that's just an example.  Note that you want
the public key (that is, what's in `id_ecdsa.pub`, not `id_ecdsa`).

Once you have the key in the config file like that, with the "key::"
prefix, Git will pull from the agent if necessary.  I do that for
signing commits using GitHub Codespaces, where it's easier to forward
an SSH agent to the remote system than with GnuPG.

This is documented in the `user.signingKey` entry in `git config
--help`, but if there's something there that's unclear or you think the
text could be improved, please say something, and we'll try to get it
fixed.
-- 
brian m. carlson (they/them or he/him)
Toronto, Ontario, CA

```

## Yarden Bar, 2024-11-14 08:57

Subject: Re: gpg-ssh signing with AgentForwarding
Message-ID: <CAJPGt+WwMWApt5o8E1nQGZnADbfjEkVmazUmxJ83Au6QPJ8Jdg@mail.gmail.com>
URL: https://gitlist.dev/e/CAJPGt%2BWwMWApt5o8E1nQGZnADbfjEkVmazUmxJ83Au6QPJ8Jdg%40mail.gmail.com
In-Reply-To: <ZyybBPigKZ_MlnU6@tapette.crustytoothpaste.net>

```
Hi all,
A colleague of mine was able to figure it out.
https://github.com/maxgoedjen/secretive/issues/405#issuecomment-2475175801
Hope it will help/serve the community

Jordan

On Thu, Nov 7, 2024 at 2:48 AM brian m. carlson
<sandals@crustytoothpaste.net> wrote:
>
> On 2024-11-07 at 04:16:34, Yarden Bar wrote:
> > Hello Git community,
> > Not sure what search terms I haven't used, but I'll try to describe the use-case
> >
> > On my local machine I have a SSH key, and I use AgentForwarding when I
> > go out and about to other hosts (dev machines)
> > The usual workflow of using the forwarded socket works for pull and push.
> >
> > Where it gets pitch-dark is when I try to use my ssh key to sign git commits.
> > Following is my git config on the remote host:
> > =====================
> > [user]
> >     name = John Doe
> >     email = jdoe@jdoe.com
> > # on my local machine(gpg-ssh signing works): signingkey =
> > /Users/jdoe/.ssh/id_ecdsa.pub
> >     signingkey = WHAT_SHOULD_I_PUT_HERE # on my laptop its the path to
> > the public key from Secretive, or just omit it?
>
> I think you want something like this:
>
>   [user]
>       signingkey = "key::ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIOMqqnkVzrm0SdG6UOoqKLsabgH5C9okWi0dh2l9GKJl"
>
> You should use your own key; that's just an example.  Note that you want
> the public key (that is, what's in `id_ecdsa.pub`, not `id_ecdsa`).
>
> Once you have the key in the config file like that, with the "key::"
> prefix, Git will pull from the agent if necessary.  I do that for
> signing commits using GitHub Codespaces, where it's easier to forward
> an SSH agent to the remote system than with GnuPG.
>
> This is documented in the `user.signingKey` entry in `git config
> --help`, but if there's something there that's unclear or you think the
> text could be improved, please say something, and we'll try to get it
> fixed.
> --
> brian m. carlson (they/them or he/him)
> Toronto, Ontario, CA

```
