pg.ddx.io  pgsql-www@postgresql.org mailing list archive  
help / color / mirror / Atom feed
Broken SSH Key Parsing
7+ messages / 2 participants
[nested] [flat]

* Broken SSH Key Parsing
@ 2026-08-11 20:08  Tristan Partin <tristan@partin.io>
  0 siblings, 1 reply; 7+ messages in thread

From: Tristan Partin @ 2026-08-11 20:08 UTC (permalink / raw)
  To: pgsql-www <pgsql-www@lists.postgresql.org>

Hey folks,

I just got access to a Git repository on postgresql.org, so I started 
going through the motions of adding an SSH key to my profile. I was 
unable to add my key as-is, so I figured that I would flag the issue. My 
public SSH key looks something like this:

	ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s= email@example.com (hostname)

Accordingto to SSH key documentation[0], an SSH key is composed of 
3 components:

	A B C

A: The key type
B: Base64-encoded public key
C: An optional comment

The problem with this key in particular is the comment. If I remove 
`(hostname)` from the key, postgresql.org will accept the key. I have 
a suspicion that we are probably incorrectly validating the key. Some 
pseudocode that would illustrate my hypothesis:

	keys = []
	for t in text.splitlines():
		sections = t.split(" ")
		if len(sections) < 2 or len(sections) > 3:
			raise ValueError("Invalid SSH key format")

		keys.append(OpenSSHKey(sections[0], sections[1], sections[2] if len(sections) == 3 else None))

I am happy to investigate this further if I can get read access to the 
postgresql.org site.

I find my current comment format, including the hostname, to be useful 
when identifying the email and machine the key belongs to. I'll work 
around it for now.

[0]: https://sshref.dev/#intro_legc_pub

-- 
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)






^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-08-17 16:08  Tristan Partin <tristan@partin.io>
  parent: Tristan Partin <tristan@partin.io>
  0 siblings, 1 reply; 7+ messages in thread

From: Tristan Partin @ 2026-08-17 16:08 UTC (permalink / raw)
  To: pgsql-www <pgsql-www@lists.postgresql.org>

On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
> Hey folks,
>
> I just got access to a Git repository on postgresql.org, so I started 
> going through the motions of adding an SSH key to my profile. I was 
> unable to add my key as-is, so I figured that I would flag the issue. My 
> public SSH key looks something like this:
>
> 	ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s= email@example.com (hostname)
>
> Accordingto to SSH key documentation[0], an SSH key is composed of 
> 3 components:
>
> 	A B C
>
> A: The key type
> B: Base64-encoded public key
> C: An optional comment
>
> The problem with this key in particular is the comment. If I remove 
> `(hostname)` from the key, postgresql.org will accept the key. I have 
> a suspicion that we are probably incorrectly validating the key. Some 
> pseudocode that would illustrate my hypothesis:
>
> 	keys = []
> 	for t in text.splitlines():
> 		sections = t.split(" ")
> 		if len(sections) < 2 or len(sections) > 3:
> 			raise ValueError("Invalid SSH key format")
>
> 		keys.append(OpenSSHKey(sections[0], sections[1], sections[2] if len(sections) == 3 else None))
>
> I am happy to investigate this further if I can get read access to the 
> postgresql.org site.
>
> I find my current comment format, including the hostname, to be useful 
> when identifying the email and machine the key belongs to. I'll work 
> around it for now.
>
> [0]: https://sshref.dev/#intro_legc_pub

Here is a patch to improve things a bit. We should probably add some 
unit tests for this.

-- 
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)

Attachments:

  [text/x-patch] v1-0001-Improve-SSH-key-parsing.patch (1.9K, ../../DKRCKXI6J43G.3MQR3PFS7KB76@partin.io/2-v1-0001-Improve-SSH-key-parsing.patch)
  download | inline diff:
From 966817a060cbda6fe2fdc802c26eb197425e6ae4 Mon Sep 17 00:00:00 2001
From: Tristan Partin <tristan@partin.io>
Date: Mon, 17 Aug 2026 15:46:40 +0000
Subject: [PATCH v1] Improve SSH key parsing

We previously rejected SSH keys with comments that included spaces.
Nothing in the SSH key specification forbids that.

Signed-off-by: Tristan Partin <tristan@partin.io>
---
 pgweb/core/models.py | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/pgweb/core/models.py b/pgweb/core/models.py
index 63eb8275..0da661da 100644
--- a/pgweb/core/models.py
+++ b/pgweb/core/models.py
@@ -258,18 +258,22 @@ def date(self):
 
 
 # Options, keytype, key, comment. But we don't support options.
-def validate_sshkey(key):
+def validate_sshkey(key: str):
     lines = key.splitlines()
     for k in lines:
-        pieces = k.split()
+        pieces = k.split(maxsplit=2)
         if len(pieces) == 0:
             raise ValidationError("Empty keys are not allowed")
-        if len(pieces) > 3:
+        if len(pieces) < 2:
             raise ValidationError('Paste each ssh key without options, e.g. "ssh-rsa AAAAbbbcc mykey@machine"')
         if pieces[0] == 'ssh-dss':
             raise ValidationError("For security reasons, ssh-dss keys are not supported")
         if pieces[0] not in _valid_keytypes:
-            raise ValidationError("Only keys of types {0} are supported, not {1}.".format(", ".join(_valid_keytypes), pieces[0]))
+            raise ValidationError(
+                'Only keys of types {0} are supported, not "{1}". '
+                'If you pasted a key with options (e.g. from an authorized_keys file), '
+                'remove the options field before the key type.'.format(", ".join(_valid_keytypes), pieces[0])
+            )
         try:
             base64.b64decode(pieces[1])
         except Exception as e:
-- 
Tristan Partin
https://tristan.partin.io



^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-08-17 19:52  Magnus Hagander <magnus@hagander.net>
  parent: Tristan Partin <tristan@partin.io>
  0 siblings, 1 reply; 7+ messages in thread

From: Magnus Hagander @ 2026-08-17 19:52 UTC (permalink / raw)
  To: Tristan Partin <tristan@partin.io>; +Cc: pgsql-www <pgsql-www@lists.postgresql.org>

On Mon, 17 Aug 2026 at 18:08, Tristan Partin <tristan@partin.io> wrote:

> On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
> > Hey folks,
> >
> > I just got access to a Git repository on postgresql.org, so I started
> > going through the motions of adding an SSH key to my profile. I was
> > unable to add my key as-is, so I figured that I would flag the issue. My
> > public SSH key looks something like this:
> >
> >       ecdsa-sha2-nistp256
> AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s=
> email@example.com (hostname)
> >
> > Accordingto to SSH key documentation[0], an SSH key is composed of
> > 3 components:
> >
> >       A B C
> >
> > A: The key type
> > B: Base64-encoded public key
> > C: An optional comment
> >
> > The problem with this key in particular is the comment. If I remove
> > `(hostname)` from the key, postgresql.org will accept the key. I have
> > a suspicion that we are probably incorrectly validating the key. Some
> > pseudocode that would illustrate my hypothesis:
> >
> >       keys = []
> >       for t in text.splitlines():
> >               sections = t.split(" ")
> >               if len(sections) < 2 or len(sections) > 3:
> >                       raise ValueError("Invalid SSH key format")
> >
> >               keys.append(OpenSSHKey(sections[0], sections[1],
> sections[2] if len(sections) == 3 else None))
> >
> > I am happy to investigate this further if I can get read access to the
> > postgresql.org site.
> >
> > I find my current comment format, including the hostname, to be useful
> > when identifying the email and machine the key belongs to. I'll work
> > around it for now.
> >
> > [0]: https://sshref.dev/#intro_legc_pub
>
> Here is a patch to improve things a bit. We should probably add some
> unit tests for this
>


Wouldn't it be safer to just cut the options if they are included? If we
don't then we have to also audit every downstream consumer of the keys
through the authentication system so they know how to deal with those keys,
since we're chagning the exchanged format there, since as it is now we just
pass it straight through.

-- 
 Magnus Hagander
 Me: https://www.hagander.net/ <http://www.hagander.net/;
 Work: https://www.redpill-linpro.com/ <http://www.redpill-linpro.com/;

^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-08-31 20:25  Tristan Partin <tristan@partin.io>
  parent: Magnus Hagander <magnus@hagander.net>
  0 siblings, 1 reply; 7+ messages in thread

From: Tristan Partin @ 2026-08-31 20:25 UTC (permalink / raw)
  To: Magnus Hagander <magnus@hagander.net>; +Cc: pgsql-www <pgsql-www@lists.postgresql.org>

On Mon Aug 17, 2026 at 7:53 PM UTC, Magnus Hagander wrote:
> On Mon, 17 Aug 2026 at 18:08, Tristan Partin <tristan@partin.io> wrote:
>
>> On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
>> > Hey folks,
>> >
>> > I just got access to a Git repository on postgresql.org, so I started
>> > going through the motions of adding an SSH key to my profile. I was
>> > unable to add my key as-is, so I figured that I would flag the issue. My
>> > public SSH key looks something like this:
>> >
>> >       ecdsa-sha2-nistp256
>> AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s=
>> email@example.com (hostname)
>> >
>> > Accordingto to SSH key documentation[0], an SSH key is composed of
>> > 3 components:
>> >
>> >       A B C
>> >
>> > A: The key type
>> > B: Base64-encoded public key
>> > C: An optional comment
>> >
>> > The problem with this key in particular is the comment. If I remove
>> > `(hostname)` from the key, postgresql.org will accept the key. I have
>> > a suspicion that we are probably incorrectly validating the key. Some
>> > pseudocode that would illustrate my hypothesis:
>> >
>> >       keys = []
>> >       for t in text.splitlines():
>> >               sections = t.split(" ")
>> >               if len(sections) < 2 or len(sections) > 3:
>> >                       raise ValueError("Invalid SSH key format")
>> >
>> >               keys.append(OpenSSHKey(sections[0], sections[1],
>> sections[2] if len(sections) == 3 else None))
>> >
>> > I am happy to investigate this further if I can get read access to the
>> > postgresql.org site.
>> >
>> > I find my current comment format, including the hostname, to be useful
>> > when identifying the email and machine the key belongs to. I'll work
>> > around it for now.
>> >
>> > [0]: https://sshref.dev/#intro_legc_pub
>>
>> Here is a patch to improve things a bit. We should probably add some
>> unit tests for this
>>
>
>
> Wouldn't it be safer to just cut the options if they are included? If we
> don't then we have to also audit every downstream consumer of the keys
> through the authentication system so they know how to deal with those keys,
> since we're chagning the exchanged format there, since as it is now we just
> pass it straight through.

Sounds reasonable. How are these SSH keys consumed? Do they just make 
their way into a Git server config somewhere?

-- 
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)





^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-08-31 20:39  Magnus Hagander <magnus@hagander.net>
  parent: Tristan Partin <tristan@partin.io>
  0 siblings, 1 reply; 7+ messages in thread

From: Magnus Hagander @ 2026-08-31 20:39 UTC (permalink / raw)
  To: Tristan Partin <tristan@partin.io>; +Cc: pgsql-www <pgsql-www@lists.postgresql.org>

On Mon, 31 Aug 2026 at 22:25, Tristan Partin <tristan@partin.io> wrote:

> On Mon Aug 17, 2026 at 7:53 PM UTC, Magnus Hagander wrote:
> > On Mon, 17 Aug 2026 at 18:08, Tristan Partin <tristan@partin.io> wrote:
> >
> >> On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
> >> > Hey folks,
> >> >
> >> > I just got access to a Git repository on postgresql.org, so I started
> >> > going through the motions of adding an SSH key to my profile. I was
> >> > unable to add my key as-is, so I figured that I would flag the issue.
> My
> >> > public SSH key looks something like this:
> >> >
> >> >       ecdsa-sha2-nistp256
> >>
> AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s=
> >> email@example.com (hostname)
> >> >
> >> > Accordingto to SSH key documentation[0], an SSH key is composed of
> >> > 3 components:
> >> >
> >> >       A B C
> >> >
> >> > A: The key type
> >> > B: Base64-encoded public key
> >> > C: An optional comment
> >> >
> >> > The problem with this key in particular is the comment. If I remove
> >> > `(hostname)` from the key, postgresql.org will accept the key. I have
> >> > a suspicion that we are probably incorrectly validating the key. Some
> >> > pseudocode that would illustrate my hypothesis:
> >> >
> >> >       keys = []
> >> >       for t in text.splitlines():
> >> >               sections = t.split(" ")
> >> >               if len(sections) < 2 or len(sections) > 3:
> >> >                       raise ValueError("Invalid SSH key format")
> >> >
> >> >               keys.append(OpenSSHKey(sections[0], sections[1],
> >> sections[2] if len(sections) == 3 else None))
> >> >
> >> > I am happy to investigate this further if I can get read access to the
> >> > postgresql.org site.
> >> >
> >> > I find my current comment format, including the hostname, to be useful
> >> > when identifying the email and machine the key belongs to. I'll work
> >> > around it for now.
> >> >
> >> > [0]: https://sshref.dev/#intro_legc_pub
> >>
> >> Here is a patch to improve things a bit. We should probably add some
> >> unit tests for this
> >>
> >
> >
> > Wouldn't it be safer to just cut the options if they are included? If we
> > don't then we have to also audit every downstream consumer of the keys
> > through the authentication system so they know how to deal with those
> keys,
> > since we're chagning the exchanged format there, since as it is now we
> just
> > pass it straight through.
>
> Sounds reasonable. How are these SSH keys consumed? Do they just make
> their way into a Git server config somewhere?
>

It's a couple of  different ones as well but fundamentally yes,that's how
they work.

-- 
 Magnus Hagander
 Me: https://www.hagander.net/ <http://www.hagander.net/;
 Work: https://www.redpill-linpro.com/ <http://www.redpill-linpro.com/;

^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-09-02 17:14  Tristan Partin <tristan@partin.io>
  parent: Magnus Hagander <magnus@hagander.net>
  0 siblings, 1 reply; 7+ messages in thread

From: Tristan Partin @ 2026-09-02 17:14 UTC (permalink / raw)
  To: Magnus Hagander <magnus@hagander.net>; +Cc: pgsql-www <pgsql-www@lists.postgresql.org>

On Mon Aug 31, 2026 at 8:39 PM UTC, Magnus Hagander wrote:
> On Mon, 31 Aug 2026 at 22:25, Tristan Partin <tristan@partin.io> wrote:
>
>> On Mon Aug 17, 2026 at 7:53 PM UTC, Magnus Hagander wrote:
>> > On Mon, 17 Aug 2026 at 18:08, Tristan Partin <tristan@partin.io> wrote:
>> >
>> >> On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
>> >> > Hey folks,
>> >> >
>> >> > I just got access to a Git repository on postgresql.org, so I started
>> >> > going through the motions of adding an SSH key to my profile. I was
>> >> > unable to add my key as-is, so I figured that I would flag the issue.
>> My
>> >> > public SSH key looks something like this:
>> >> >
>> >> >       ecdsa-sha2-nistp256
>> >>
>> AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s=
>> >> email@example.com (hostname)
>> >> >
>> >> > Accordingto to SSH key documentation[0], an SSH key is composed of
>> >> > 3 components:
>> >> >
>> >> >       A B C
>> >> >
>> >> > A: The key type
>> >> > B: Base64-encoded public key
>> >> > C: An optional comment
>> >> >
>> >> > The problem with this key in particular is the comment. If I remove
>> >> > `(hostname)` from the key, postgresql.org will accept the key. I have
>> >> > a suspicion that we are probably incorrectly validating the key. Some
>> >> > pseudocode that would illustrate my hypothesis:
>> >> >
>> >> >       keys = []
>> >> >       for t in text.splitlines():
>> >> >               sections = t.split(" ")
>> >> >               if len(sections) < 2 or len(sections) > 3:
>> >> >                       raise ValueError("Invalid SSH key format")
>> >> >
>> >> >               keys.append(OpenSSHKey(sections[0], sections[1],
>> >> sections[2] if len(sections) == 3 else None))
>> >> >
>> >> > I am happy to investigate this further if I can get read access to the
>> >> > postgresql.org site.
>> >> >
>> >> > I find my current comment format, including the hostname, to be useful
>> >> > when identifying the email and machine the key belongs to. I'll work
>> >> > around it for now.
>> >> >
>> >> > [0]: https://sshref.dev/#intro_legc_pub
>> >>
>> >> Here is a patch to improve things a bit. We should probably add some
>> >> unit tests for this
>> >>
>> >
>> >
>> > Wouldn't it be safer to just cut the options if they are included? If we
>> > don't then we have to also audit every downstream consumer of the keys
>> > through the authentication system so they know how to deal with those
>> keys,
>> > since we're chagning the exchanged format there, since as it is now we
>> just
>> > pass it straight through.
>>
>> Sounds reasonable. How are these SSH keys consumed? Do they just make
>> their way into a Git server config somewhere?
>>
>
> It's a couple of  different ones as well but fundamentally yes,that's how
> they work.

What are your thoughts on reworking the UI/UX for saving SSH keys on 
postgresql.org? I'm thinking we could take a more GitHub-like approach. 
User adds one key at a time instead of the \n deliminated text entry 
that we currently have. I think it would make it easier to understand 
which SSH key is causing a failure. Additionally, I think it would make 
the validation process a bit nicer.

-- 
Tristan Partin
PostgreSQL Contributors Team
AWS (https://aws.amazon.com)






^ permalink  raw  reply  [nested|flat] 7+ messages in thread

* Re: Broken SSH Key Parsing
@ 2026-09-07 14:05  Magnus Hagander <magnus@hagander.net>
  parent: Tristan Partin <tristan@partin.io>
  0 siblings, 0 replies; 7+ messages in thread

From: Magnus Hagander @ 2026-09-07 14:05 UTC (permalink / raw)
  To: Tristan Partin <tristan@partin.io>; +Cc: pgsql-www <pgsql-www@lists.postgresql.org>

On Wed, 2 Sept 2026 at 19:14, Tristan Partin <tristan@partin.io> wrote:

> On Mon Aug 31, 2026 at 8:39 PM UTC, Magnus Hagander wrote:
> > On Mon, 31 Aug 2026 at 22:25, Tristan Partin <tristan@partin.io> wrote:
> >
> >> On Mon Aug 17, 2026 at 7:53 PM UTC, Magnus Hagander wrote:
> >> > On Mon, 17 Aug 2026 at 18:08, Tristan Partin <tristan@partin.io>
> wrote:
> >> >
> >> >> On Tue Aug 11, 2026 at 8:08 PM UTC, Tristan Partin wrote:
> >> >> > Hey folks,
> >> >> >
> >> >> > I just got access to a Git repository on postgresql.org, so I
> started
> >> >> > going through the motions of adding an SSH key to my profile. I was
> >> >> > unable to add my key as-is, so I figured that I would flag the
> issue.
> >> My
> >> >> > public SSH key looks something like this:
> >> >> >
> >> >> >       ecdsa-sha2-nistp256
> >> >>
> >>
> AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBDPYnw8WWCrgL0sXijK7BY1Qz7KJlQZNe+ErNNwmfqazAd/CuTNNdENj21R6iR2CsjoEZ1prFcj/hPDV/j4nf7s=
> >> >> email@example.com (hostname)
> >> >> >
> >> >> > Accordingto to SSH key documentation[0], an SSH key is composed of
> >> >> > 3 components:
> >> >> >
> >> >> >       A B C
> >> >> >
> >> >> > A: The key type
> >> >> > B: Base64-encoded public key
> >> >> > C: An optional comment
> >> >> >
> >> >> > The problem with this key in particular is the comment. If I remove
> >> >> > `(hostname)` from the key, postgresql.org will accept the key. I
> have
> >> >> > a suspicion that we are probably incorrectly validating the key.
> Some
> >> >> > pseudocode that would illustrate my hypothesis:
> >> >> >
> >> >> >       keys = []
> >> >> >       for t in text.splitlines():
> >> >> >               sections = t.split(" ")
> >> >> >               if len(sections) < 2 or len(sections) > 3:
> >> >> >                       raise ValueError("Invalid SSH key format")
> >> >> >
> >> >> >               keys.append(OpenSSHKey(sections[0], sections[1],
> >> >> sections[2] if len(sections) == 3 else None))
> >> >> >
> >> >> > I am happy to investigate this further if I can get read access to
> the
> >> >> > postgresql.org site.
> >> >> >
> >> >> > I find my current comment format, including the hostname, to be
> useful
> >> >> > when identifying the email and machine the key belongs to. I'll
> work
> >> >> > around it for now.
> >> >> >
> >> >> > [0]: https://sshref.dev/#intro_legc_pub
> >> >>
> >> >> Here is a patch to improve things a bit. We should probably add some
> >> >> unit tests for this
> >> >>
> >> >
> >> >
> >> > Wouldn't it be safer to just cut the options if they are included? If
> we
> >> > don't then we have to also audit every downstream consumer of the keys
> >> > through the authentication system so they know how to deal with those
> >> keys,
> >> > since we're chagning the exchanged format there, since as it is now we
> >> just
> >> > pass it straight through.
> >>
> >> Sounds reasonable. How are these SSH keys consumed? Do they just make
> >> their way into a Git server config somewhere?
> >>
> >
> > It's a couple of  different ones as well but fundamentally yes,that's how
> > they work.
>
> What are your thoughts on reworking the UI/UX for saving SSH keys on
> postgresql.org? I'm thinking we could take a more GitHub-like approach.
> User adds one key at a time instead of the \n deliminated text entry
> that we currently have. I think it would make it easier to understand
> which SSH key is causing a failure. Additionally, I think it would make
> the validation process a bit nicer.
>

Yeah, that would definitely be an improvement I think! The current one is
basically a "quick-fix, we didn't originally think of the need to have more
than one key".

-- 
 Magnus Hagander
 Me: https://www.hagander.net/ <http://www.hagander.net/;
 Work: https://www.redpill-linpro.com/ <http://www.redpill-linpro.com/;

^ permalink  raw  reply  [nested|flat] 7+ messages in thread


end of thread, other threads:[~2026-09-07 14:05 UTC | newest]

Thread overview: 7+ messages (download: mbox mbox.gz follow: Atom feed)
-- links below jump to the message on this page --
2026-08-11 20:08 Broken SSH Key Parsing Tristan Partin <tristan@partin.io>
2026-08-17 16:08 ` Tristan Partin <tristan@partin.io>
2026-08-17 19:52   ` Magnus Hagander <magnus@hagander.net>
2026-08-31 20:25     ` Tristan Partin <tristan@partin.io>
2026-08-31 20:39       ` Magnus Hagander <magnus@hagander.net>
2026-09-02 17:14         ` Tristan Partin <tristan@partin.io>
2026-09-07 14:05           ` Magnus Hagander <magnus@hagander.net>

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox