Git hosting and ed25519-sk
Quick look if major Git hosting providers are up-to-date about security.
The possibility to use ed25519-sk is a critical point when evaluating Git hosting.
ed25519-sk
When you generate this type of key, you need your physical security key,
You obtain this type of output:
)
The most important part is You may need to touch your authenticator to authorize key generation.
Each time that you’ll want to use this key, you’ll need your physical security key (Yubikey & co) otherwise it’ll be impossible.
For critical accounts/repositories, it must be enforced with 1 to 3 spares stored in different safe places. Yes, you’ll need to generate an ed25519-sk with each but it’s nothing compared to losing your access.
Git hosting
⛔ Bitbucket
It’s not a surprise, Bitbucket doesn’t implement it.
🎉 Gitea
Gitea is up-to-date about ed25519-sk.
Tested on my personal Git server (self-hosted)
⛔ Gitee
Gitee, the Chinese platform (OSChina is the owner) doesn’t implement it.
🎉 GitHub
Of course, GitHub is up-to-date about security.
🎉 GitLab
Tested on gitlab.com, and it’s working fine.
If your self-hosted Gitea/GitLab doesn’t support ed25519-sk, just update it and have an OpenSSH server >= 8.2.