Briefing

ssh‑tpm‑agent v0.9.0 Release: Signed Tarball, Confirmation Prompt, and Public Key Permissions Updated

security
by github.com by Foxboron ·

Download the signed v0.9.0 tarball and enable per‑use confirmation with the -c flag.

What to do now

Download the signed tarball from GitHub and update your ssh‑tpm‑agent to v0.9.0.

Summary

The ssh‑tpm‑agent project has released version 0.9.0, a signed tarball that includes an embedded version and a VERSION file. Public keys are now stored with world‑readable 644 permissions, matching the behaviour of ssh‑keygen. The ssh‑askpass prompt has been enhanced to display the process chain that triggered the confirmation dialog. A new -c flag for ssh‑tpm‑add enables per‑use confirmation, requiring user interaction through ssh‑askpass before a key is used. The release also eliminates data races when the keyring returns ENOENT, treating it as ENOKEY. Minor typos in the README and documentation have been fixed, and the changelog now includes detailed entries. The agent now shows the requesting process in the confirmation prompt, improving transparency. Users should download the signed tarball from the GitHub release and update their ssh‑tpm‑agent to v0.9.0.

Key changes

  • Signed release v0.9.0 with embedded version
  • Public keys now 644 permissions
  • ssh‑askpass shows process chain
  • ssh‑tpm‑add supports -c flag for confirmation
  • Data races eliminated when keyring returns ENOENT
  • Minor typos fixed in README
  • Agent shows requesting process in confirm prompt
  • Download signed tarball to update agent

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting