diff options
Diffstat (limited to 'modules/security/gopass/gopass-ssh-load.sh')
| -rw-r--r-- | modules/security/gopass/gopass-ssh-load.sh | 23 |
1 files changed, 22 insertions, 1 deletions
diff --git a/modules/security/gopass/gopass-ssh-load.sh b/modules/security/gopass/gopass-ssh-load.sh index e974713..b9a06e9 100644 --- a/modules/security/gopass/gopass-ssh-load.sh +++ b/modules/security/gopass/gopass-ssh-load.sh @@ -1,9 +1,30 @@ #!/usr/bin/env bash + +# gopass-ssh-load +# +# Load SSH keys into the SSH agent from the gopass password store. +# +# This script reads private keys and (optionally) their passphrases from gopass +# entries under the `ssh/` directory and adds them to the SSH agent served by +# gpg-agent. It is meant to be run manually whenever a key is imported into or +# rotated within the gopass store, so the SSH agent picks up the change. +# +# Behaviour: +# * It first verifies that a usable SSH agent socket exists and bails out if +# not. +# * It exits early (without doing anything) when the agent already has at +# least one Ed25519/RSA/ECDSA identity loaded, to avoid useless work and +# unnecessary gpg passphrase prompts. +# * For each key listed in GOPASS_SSH_KEYS it writes the corresponding +# `ssh/<key>` entry to a temporary file, strips the passphrase using the +# `ssh/<key>/passphrase` entry, and registers the key with `ssh-add`. +# +# Temporary key files are written with mode 600 and removed afterwards. + set -o errexit set -o nounset set -o pipefail -# Load SSH keys from gopass password store export GNUPGHOME="@@GNUPGHOME@@" export GOPASS_SSH_KEYS="@@GOPASS_SSH_KEYS@@" |
