ecdsa_sk ssh key verified on Gitea – Unable to connect #1

Closed
opened 2026-04-27 16:58:07 +00:00 by Golffies · 2 comments

Hi,

Gitea accepts my FIDO2 ecdsa_sk ssh key (see screenshot). Furthermore, its ssh server confirms that it supports the ecdsa_sk algorithm:

debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>

For some reason, SSH key authentication fails, and the system falls back to password authentication. I’ve attached the debug messages from my SSH client below:

$ ssh -v -i ~/.ssh/id_ecdsa_sk-2026-04-27 -T git@git.kolibrios.org
OpenSSH_8.9p1 Ubuntu-3ubuntu0.14, OpenSSL 3.0.2 15 Mar 2022
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to git.kolibrios.org [72.62.2.57] port 22.
debug1: Connection established.
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27 type 10
debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.14
debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.15
debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 pat OpenSSH* compat 0x04000000
debug1: Authenticating to git.kolibrios.org:22 as 'git'
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:JHJiAVwwXUqIWrILpV6sKL/DYMggq/91Gc7AjzW5YAs
debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host 'git.kolibrios.org' is known and matches the ED25519 host key.
debug1: Found key in /home/interface/.ssh/known_hosts:1
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: get_agent_identities: bound agent to hostkey
debug1: get_agent_identities: agent returned 1 keys
debug1: Will attempt key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256>
debug1: kex_input_ext_info: publickey-hostbound@openssh.com=<0>
debug1: kex_input_ext_info: ping@openssh.com (unrecognised)
debug1: SSH2_MSG_SERVICE_ACCEPT received
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: publickey
debug1: Offering public key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent
debug1: Authentications that can continue: publickey,password
debug1: Next authentication method: password
git@git.kolibrios.org's password:

The issue might look similar to the one reported here, but does not display the same error message; more importantly, a fix was apparently implemented in Gitea in December 2023, well before the current version 1.26.

Another related bug report concerns the tea client, not Gitea itself. It’s not really relevant.

Is there anything in the sshd_config file on the server that might be causing the issue?

Hi, Gitea accepts my `FIDO2 ecdsa_sk` ssh key (see screenshot). Furthermore, its `ssh` server confirms that it supports the `ecdsa_sk` algorithm: > debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,**sk-ecdsa-sha2-nistp256@openssh.com**,rsa-sha2-512,rsa-sha2-256> For some reason, SSH key authentication fails, and the system falls back to password authentication. I’ve attached the debug messages from my SSH client below: ``` $ ssh -v -i ~/.ssh/id_ecdsa_sk-2026-04-27 -T git@git.kolibrios.org OpenSSH_8.9p1 Ubuntu-3ubuntu0.14, OpenSSL 3.0.2 15 Mar 2022 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 19: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: /etc/ssh/ssh_config line 21: Applying options for * debug1: Connecting to git.kolibrios.org [72.62.2.57] port 22. debug1: Connection established. debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27 type 10 debug1: identity file /home/interface/.ssh/id_ecdsa_sk-2026-04-27-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.14 debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 debug1: compat_banner: match: OpenSSH_9.6p1 Ubuntu-3ubuntu13.15 pat OpenSSH* compat 0x04000000 debug1: Authenticating to git.kolibrios.org:22 as 'git' debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: curve25519-sha256 debug1: kex: host key algorithm: ssh-ed25519 debug1: kex: server->client cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: kex: client->server cipher: chacha20-poly1305@openssh.com MAC: <implicit> compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: SSH2_MSG_KEX_ECDH_REPLY received debug1: Server host key: ssh-ed25519 SHA256:JHJiAVwwXUqIWrILpV6sKL/DYMggq/91Gc7AjzW5YAs debug1: load_hostkeys: fopen /home/interface/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host 'git.kolibrios.org' is known and matches the ED25519 host key. debug1: Found key in /home/interface/.ssh/known_hosts:1 debug1: ssh_packet_send2_wrapped: resetting send seqnr 3 debug1: rekey out after 134217728 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: ssh_packet_read_poll2: resetting read seqnr 3 debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 134217728 blocks debug1: get_agent_identities: bound agent to hostkey debug1: get_agent_identities: agent returned 1 keys debug1: Will attempt key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent debug1: SSH2_MSG_EXT_INFO received debug1: kex_input_ext_info: server-sig-algs=<ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,sk-ssh-ed25519@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com,rsa-sha2-512,rsa-sha2-256> debug1: kex_input_ext_info: publickey-hostbound@openssh.com=<0> debug1: kex_input_ext_info: ping@openssh.com (unrecognised) debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey,password debug1: Next authentication method: publickey debug1: Offering public key: /home/interface/.ssh/id_ecdsa_sk-2026-04-27 ECDSA-SK SHA256:78UamyfSEQijo6H/6LNhI5yy5ZJLG2i+mRseFlucPyo explicit authenticator agent debug1: Authentications that can continue: publickey,password debug1: Next authentication method: password git@git.kolibrios.org's password: ``` The issue might look similar to the one reported [here](https://forum.gitea.com/t/ssh-key-is-not-being-accepted/11337/4), but does not display the same error message; more importantly, a fix was apparently implemented in Gitea in December 2023, well before the current version 1.26. Another [related bug report](https://gitea.com/gitea/tea/issues/556) concerns the tea client, not Gitea itself. It’s not really relevant. Is there anything in the `sshd_config` file on the server that might be causing the issue?
Owner

Salut. Gitea's SSH on port 222

Salut. Gitea's SSH on port 222
Author

Well,

It wasn't a bug, but a feature. Undocumented.

Thank you for your reply, and for your efforts in keeping Gitea up to date. But I must admit I feel a bit frustrated about the time I’ve wasted.

Well, > It wasn't a bug, but a feature. _Undocumented._ Thank you for your reply, and for your efforts in keeping Gitea up to date. But I must admit I feel a bit frustrated about the time I’ve wasted.
Sign in to join this conversation.
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: KolibriOS/gitea-kolibrios#1