# How to use ECDSA ssh key to connect to Github private repo?

**URL:** <https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372>\
**Category:** General Usage\
**Tags:** pkg, ssh\
**Created:** [January 11, 2022, 2:30am UTC](https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372 "2022-01-11T02:30:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![metab0t](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/metab0t/32/15551_2.png) [@metab0t](https://discourse.julialang.org/u/metab0t)\
**Post date:** [January 11, 2022, 2:30am UTC](https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372/1 "2022-01-11T02:30:57Z")

</div>

I used to use a private Github repo as my personal registry.  
I followed the instructions in [https://github.com/GunnarFarneback/LocalRegistry.jl/blob/master/docs/ssh\_keys.md#3-generating-a-compatible-key](https://github.com/GunnarFarneback/LocalRegistry.jl/blob/master/docs/ssh_keys.md#3-generating-a-compatible-key) to generate a RSA key stored in PEM format and set up the environment variable `SSH_PUB_KEY_PATH` and `SSH_KEY_PATH`.

It works fine for months. However, it starts to break today because [the SSH key policy upgrade of Github](https://github.blog/2021-09-01-improving-git-protocol-security-github/#libgit2-and-other-git-clients).

It says that

> If you’re using libgit2 or another piece of code using libssh2, we recommend you use libssh2 1.9.0 or newer and an ECDSA key, since it does not yet support RSA with SHA-2. Similarly, the Go SSH client also doesn’t yet support RSA with SHA-2, so we recommend using an Ed25519 key there

I generate a new ECDSA key with `ssh-keygen`

```bash
ssh-keygen -m PEM -t ECDSA

```

The generated key starts with `-----BEGIN EC PRIVATE KEY-----`

Then I change the environment variable `SSH_PUB_KEY_PATH` and `SSH_KEY_PATH` to point at new ECDSA key pair.

It seems that Julia cannot recognize ECDSA key but its libssh version is 1.9.0.

The platform I use is Windows 10 and the julia version is

```julia
julia> versioninfo()
Julia Version 1.7.1
Commit ac5cc99908 (2021-12-22 19:35 UTC)
Platform Info:
  OS: Windows (x86_64-w64-mingw32)
  CPU: AMD Ryzen 7 5800H with Radeon Graphics
  WORD_SIZE: 64
  LIBM: libopenlibm
  LLVM: libLLVM-12.0.1 (ORCJIT, znver3)
Environment:
  JULIA_NUM_THREADS = 16

```

---

<div class="post-metadata">

**Author:** ![GunnarFarneback](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/gunnarfarneback/32/1827_2.png) [@GunnarFarneback](https://discourse.julialang.org/u/GunnarFarneback)\
**Post date:** [January 11, 2022, 7:47pm UTC](https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372/2 "2022-01-11T19:47:37Z")

</div>

I have no insights about ECDSA keys but if you cannot get it to work, Julia 1.7 provides the new option of using an external git executable to bypass `libgit2` and `libssh2` entirely. This is the relevant release notes item:

> It is now possible to use an external git executable instead of the default libgit2 library for the downloads that happen via the Git protocol by setting the environment variable `JULIA_PKG_USE_CLI_GIT=true`.

---

<div class="post-metadata">

**Author:** ![metab0t](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/metab0t/32/15551_2.png) [@metab0t](https://discourse.julialang.org/u/metab0t)\
**Post date:** [January 12, 2022, 1:26am UTC](https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372/3 "2022-01-12T01:26:45Z")

</div>

Thanks!  
I use this option and it works seamlessly.

By the way, there are many “Unlink file … failed” warning during the first run after switching to system git, I solve this problem by run `set GIT_ASK_YESNO=false` in the command line before start Julia

---

<div class="post-metadata">

**Author:** ![metab0t](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/metab0t/32/15551_2.png) [@metab0t](https://discourse.julialang.org/u/metab0t)\
**Post date:** [January 12, 2022, 12:33pm UTC](https://discourse.julialang.org/t/how-to-use-ecdsa-ssh-key-to-connect-to-github-private-repo/74372/4 "2022-01-12T12:33:07Z")

</div>

As a side note, I find that [ECDSA support for mbedTLS is introduced in libssh2 1.10.0](https://github.com/libssh2/libssh2/commit/5528f3da02eba1de425535481de049b21c48e9eb) but Julia currently uses 1.9.0.  
[This issue](https://github.com/JuliaLang/julia/issues/40297) discusses the same problem.
