# Using with AWS CodeCommit

**URL:** <https://onlykey.discourse.group/t/using-with-aws-codecommit/569>\
**Category:** SSH, OpenPGP, GPG\
**Created:** [December 21, 2021, 8:45pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569 "2021-12-21T20:45:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gh0st026](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@gh0st026](https://onlykey.discourse.group/u/gh0st026)\
**Post date:** [December 21, 2021, 8:45pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/1 "2021-12-21T20:45:07Z")

</div>

Currently AWS CodeCommit requires an RSA SSH Key (ED25519 not supported) when connecting to the git repos. However, the way CodeCommit works is it generates a random user that you will need to use when connecting to codecommit AFTER you upload your SSH Key to AWS CodeCommit. Therefore, we have no idea what the USER@HOST will be until after the key has been provided to AWS. How can onlykey be used in this scenario?

---

<div class="post-metadata">

**Author:** ![t11](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@t11](https://onlykey.discourse.group/u/t11)\
**Post date:** [December 22, 2021, 1:32am UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/2 "2021-12-22T01:32:34Z")

</div>

The onlykey-agent does support RSA keys as stored keys - [OnlyKey SSH/GPG agent | Docs](https://docs.crp.to/onlykey-agent.html#rsa)

It sounds like if CodeCommit is generating a random user then its not using the user you specify in your SSH public key anyway. It sounds like it just ignores the user@host you specify in your public key if it is then generating a random username. If this is the case you would:

- Load your RSA signing key into OnlyKey
- Generate public key (using any username as it’s ignored) i.e.

```auto
onlykey-agent user@host -e rsa -sk RSA2

```

- Upload your public key
- Find out what the random username it assigns is
- From then on use onlykey-agent with that i.e.

```auto
onlykey-agent -c randomuser@host -e rsa -sk RSA2

```

---

<div class="post-metadata">

**Author:** ![gh0st026](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@gh0st026](https://onlykey.discourse.group/u/gh0st026)\
**Post date:** [December 24, 2021, 7:01pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/3 "2021-12-24T19:01:04Z")

</div>

running

```auto
onlykey-agent user@host -e rsa -sk RSA2

```

Errors

```auto
libagent.device.interface.DeviceError: Error response length is not a valid public key

```

I tried creating new keys in gnuPG and then loaded the encryption key to RSA slot 1 with “use for decryption” selected and the signing key to RSA slot 2 with “use for signing” selected to onlykey for measure but still same error.

---

<div class="post-metadata">

**Author:** ![gh0st026](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@gh0st026](https://onlykey.discourse.group/u/gh0st026)\
**Post date:** [December 24, 2021, 8:47pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/4 "2021-12-24T20:47:13Z")

</div>

I have a backup onlykey that I just completely wiped and installed fresh with the v2.1.1 STD firmware. I didn’t load any custom keys and tried it and same error.

---

<div class="post-metadata">

**Author:** ![gh0st026](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@gh0st026](https://onlykey.discourse.group/u/gh0st026)\
**Post date:** [December 24, 2021, 8:49pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/5 "2021-12-24T20:49:25Z")

</div>

I am running ubuntu desktop 20.04.

---

<div class="post-metadata">

**Author:** ![t11](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@t11](https://onlykey.discourse.group/u/t11)\
**Post date:** [December 26, 2021, 6:54pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/6 "2021-12-26T18:54:28Z")

</div>

What size RSA key are you using. RSA-2048 and RSA-4096 are supported.

---

<div class="post-metadata">

**Author:** ![gh0st026](https://avatars.discourse-cdn.com/v4/letter/g/ecd19e/32.png) [@gh0st026](https://onlykey.discourse.group/u/gh0st026)\
**Post date:** [December 26, 2021, 7:19pm UTC](https://onlykey.discourse.group/t/using-with-aws-codecommit/569/7 "2021-12-26T19:19:53Z")

</div>

I generated an RSA-4096 key for E, S and A using gnuPG on ubuntu. works fine on yubikey
