Git SSH and Commit Signing Setup in WSL Ubuntu
Aight! It happened again! Mysteriously git just straight up stopped working for pulling/pushing on one of my WSL Ubuntu instances! I’ve just gone through setting up a fresh WSL Ubuntu 24.04 install and wanted to detail the process of getting Git configured with SSH authentication and commit signing. I’ll go through the entire process of setting this up from scratch.
1Password SSH client
“So, what happened yo?” Well, seeing as you asked! I’m not certain but pretty sure it’s 1Password and the SSH client. I was merrily going round and creating all the SSH keys with the super duper 1Password integration then one day they stopped working.
This was a while back when I posted this, but, there was a recent update to 1Password that I installed. So, pretty sus that I can no longer authenticate with my SSH keys, right?
David Flanagan is the goat when it comes to git related questions and he always has a good solution! This time, less is more!
I’ll be doing this progressively, as I go through the various VPS’ I log into I’ll be replacing the many SSH keys I’ve generated with 1Password with the one key to rule them all!
Prerequisites
I’ve already got the SSH key I’m going to use here in 1Password, so this is a copy paste operation of the existing public and private keys. If you want to get set up with creating a new SSH key, you can do so with the following command:
1ssh-keygen -t ed25519 -C "[email protected]"I already have the key added on GitHub as an authentication key and signing key, you can find your SSH and GPG keys over on GitHub under your profile settings.
If you’re starting with no SSH keys follow the guide I made a while back to Set up SSH for use with Git
Why Ed25519?
I’m using Ed25519 for this guide as it’s considered more modern and secure than RSA while being shorter and equally (or more) secure. If you’re setting up fresh, this is the way to go.
Setting up SSH for GitHub
So, remember, I’m on a new install of Ubuntu 24.04 here, so, no SSH directory set up or anything! First up, I’ll get the SSH directory created with the correct permissions:
1mkdir -p ~/.ssh
2chmod 700 ~/.sshNow, create the SSH key files with the right permissions as well, the
file name here id_ed25519 can be whatever you want it to be:
1touch ~/.ssh/id_ed25519
2touch ~/.ssh/id_ed25519.pub
3chmod 600 ~/.ssh/id_ed25519
4chmod 644 ~/.ssh/id_ed25519.pubAfter adding my keys to these files, start the SSH agent and add my key:
1eval "$(ssh-agent -s)"
2ssh-add ~/.ssh/id_ed25519Testing GitHub Connection
To verify everything’s working, I’ll run:
1ssh -T git@github.comIf you’re doing this you should see a success message from GitHub confirming your authentication is working.
Setting up Git Config with SSH Signing
Now for the interesting bit! I’ll configure Git to use SSH for both authentication and commit signing. Here’s my Git config that I’ve been using for a while now:
1# User details
2[user]
3 name = username
4 email = [email protected]
5 signingkey = /home/username/.ssh/id_ed25519
6
7# Help with typos
8[help]
9 autoCorrect = 20
10
11# Pull settings
12[pull]
13 ff = only
14 rebase = true
15
16# Default branch name
17[init]
18 defaultBranch = main
19
20# Fix conflicts only once
21[rerere]
22 enabled = true
23
24# Auto prune when fetching
25[fetch]
26 prune = true
27
28# GPG settings for SSH signing
29[gpg]
30 format = ssh
31
32[commit]
33 gpgsign = trueThe signingkey is pointing to the private key location.
Setting up SSH Signing
For commit signing to work, I’ll need to create an allowed signers file:
1touch ~/.ssh/allowed_signersAdd my key to the allowed signers file:
1echo "[email protected] ssh-ed25519 X_KEY_GOES_HERE_X" > ~/.ssh/allowed_signersThen tell Git about the allowed signers file:
1git config --global gpg.ssh.allowedSignersFile ~/.ssh/allowed_signersThe last command will add the reference to the allowed signers file to enable commit signing.
1[gpg "ssh"]
2 allowedSignersFile = /home/username/.ssh/allowed_signersTesting Commit Signing
To test that everything’s working:
1# Create a test directory
2mkdir ~/git-signing-test
3cd ~/git-signing-test
4git init
5
6# Create a test file
7echo "# Test signing" > README.md
8git add README.md
9
10# Commit with signing
11git commit -m "test: verify commit signing"
12
13# Verify the signature
14git log --show-signature -1I then see output confirming the commit was signed successfully, something like:
1commit a35a8bedf3d85e31a504a406756792e98f7d60c9 (HEAD -> main)
2Good "git" signature for username@example.com with ED25519 key SHA256:X_KEY_GOES_HERE_X
3Author: username <username@example.com>
4Date: Mon Jan 27 19:08:48 2025 +0000
5
6 test: verify commit signingSweet!
Adding Multiple SSH Configs
Now, as I have to sign into many VPS instances I have to specify them, I was using 1Password for this but I’ve cone back to the classic config now as I can’t trust 1Password SSH client not to mess it up!
Here’s an example setup:
1# Create the config file if it doesn't exist
2touch ~/.ssh/config
3chmod 600 ~/.ssh/configThen add your configurations:
1Host server_1
2 HostName your-ip-here
3 User admin
4 IdentityFile ~/.ssh/id_server_1
5 Port 22
6
7Host server_2
8 Hostname your-ip-here
9 User admin
10 IdentityFile ~/.ssh/id_server_2
11 Port 22Don’t forget to create and set permissions for the keys! Same as before:
1touch ~/.ssh/id_server_1
2chmod 600 ~/.ssh/id_server_1Again, this is presuming that you’ve already got the keys in 1Password.
If you also want to manage pull requests and issues from the terminal, here’s how I install the GitHub CLI in WSL. Its login flow is separate from the SSH and signing setup here.
That’s it!
Now I’ve got:
- SSH authentication working with GitHub
- Commit signing set up with a Ed25519 key
- A clean Git config with some nice defaults
- Additional SSH configs for other services
All of this without relying on 1Password to do the work I can’t trust it with anymore! 😅
There's a reactions leaderboard you can check out too.
Sign up for the newsletter
Want to keep up to date with what I'm working on?
Join other developers and sign up for the newsletter.
I care about the protection of your data. Read the Privacy Policy for more info.