Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding support for ssh keys for encryption. #692

Open
Mic92 opened this issue Jul 9, 2020 · 8 comments · May be fixed by #1692
Open

Adding support for ssh keys for encryption. #692

Mic92 opened this issue Jul 9, 2020 · 8 comments · May be fixed by #1692

Comments

@Mic92
Copy link
Contributor

Mic92 commented Jul 9, 2020

SSH keys could be also used for encryption. They are already in well-known locations i.e. /etc/ssh/ssh_host_rsa_key. Most developer/servers have already ssh keys.
Since most users also have ways of trusting those ssh keys (TOFU, DNS, hosters like github/gitlab or certificates) importing them should be easy. For my project I am thinking about converting ssh keys to gpg keys. However it would be probably also beneficial for sops itself to have this supported out-of-the box. I think usability of ssh-keygen over gpg is out of question.

@Mic92
Copy link
Contributor Author

Mic92 commented Jul 9, 2020

Here is some boilercode to convert ssh keys to gpg: https://gist.github.com/Mic92/24c40996cd97cb8edd53fd688c60ab6f

@jvehent
Copy link
Contributor

jvehent commented Jul 9, 2020

I agree with the initial request of using SSH keys for encryption, and #688 will give us that because age supports ssh keys.

The PGP key storage format is an abomination and it would be a mistake to add more complexity. Ultimately, we need to steer people away from PGP entirely.

@gzm55
Copy link

gzm55 commented Sep 29, 2020

@jvehent unfortunately, #688 missing ssh keys supports

@Mic92
Copy link
Contributor Author

Mic92 commented Oct 4, 2020

I will built a tool eventually to convert ed25519 as well to age keys, like I did for gpg.

@D3vl0per
Copy link

Bump?

@Mic92
Copy link
Contributor Author

Mic92 commented Jun 21, 2022

I have built: https://github.com/Mic92/ssh-to-age https://github.com/Mic92/ssh-to-pgp/ for use with sops. ssh-to-age can be used for ed25519 keys and ssh-to-pgp for rsa-based ssh keys.

@childnode
Copy link

childnode commented Jan 16, 2024

@Mic92 does your implementation literaly the same as https://github.com/FiloSottile/age/blob/main/agessh/agessh.go#L190 << https://blog.filippo.io/using-ed25519-keys-for-encryption age internally does on providing an ssh-ed25519 wrapping it into a X25519 curve encoded as Bech32 with HRP AGE-SECRET-KEY-?! looks like you copied some code and redistributed it under MIT without copyleft while age provided it under BSD 🤔

@Mic92
Copy link
Contributor Author

Mic92 commented Jan 16, 2024

BSD and MIT are compatible with each other.

@felixfontein felixfontein linked a pull request Dec 24, 2024 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants