SSH client config for macOS, Linux and Windows: per-host key selection for GitHub, agent settings and an allowed signers example for verifying signed commits.
A dedicated auth key per host, a separate signing key and an allowed_signers list that covers
every machine you sign from. This repo holds the client-side config and never a private key, so a
new machine gets the correct setup in a few steps.
<platform>/config-Hostblocks pointinggithub.comandgist.github.comat a dedicated auth key withIdentitiesOnly yes, so SSH never falls back to offering the wrong key first.AddKeysToAgent yesmeans a passphrase is only asked for once per session.allowed_signers.example- the format of the file Git reads to verify SSH commit signatures locally, with placeholders for your own email and public key. See guides/reference.md..gitignore- blocks any filename shaped like a private key, as a backstop.
UseKeychain yes is an Apple-only OpenSSH directive that stores key passphrases in the macOS
Keychain, so it only appears in mac/config. OpenSSH on Linux and Windows rejects that line as an
unknown option, so linux/ and windows/ drop it and rely on ssh-agent alone.
Caution
None of this ships a private key. Nothing here should ever hold one. .gitignore blocks
private-key-shaped filenames and CI fails on any private key header in the tree.
git clone https://github.com/zaccesss/ssh-config.git ~/.ssh-config-src
cp ~/.ssh-config-src/<platform>/config ~/.ssh/config
chmod 600 ~/.ssh/configReplace <platform> with mac, linux or windows. See guides/setup.md for
generating your own key pairs and setting up allowed_signers.
| Path | Contents |
|---|---|
mac/ |
Config with UseKeychain |
linux/ |
Config without UseKeychain |
windows/ |
Config without UseKeychain |
allowed_signers.example |
Allowed signers format with placeholders |
guides/ |
Key generation walkthrough and reference |