I have been using Bitbucket since 2012, long before my company moved from in-house hosted server running Gitolite and in-house instances of FishEye and Crucible to cloud based source control on Bitbucket Cloud. As legacy I was using my personal login with my gmail account as my Bitbucket identity.
With merge of 3 companies in 2018 and rebranding as Pivotree, we are in process of streamlining the identity management and using SSO for identification. Time has come to split my personal identity and work identity.
After re-creating the SSH key, I got the above error from Gitolite.
Full trace:
➜ TWC ssh -v thinkwrap@pensieve.thinkwrap.com OpenSSH_5.3p1, OpenSSL 1.0.1e-fips 11 Feb 2013 debug1: Reading configuration data /etc/ssh/ssh_config debug1: Applying options for * debug1: Connecting to pensieve.thinkwrap.com [24.137.198.18] port 22. debug1: Connection established. debug1: identity file /home/thinkwrap/.ssh/identity type -1 debug1: identity file /home/thinkwrap/.ssh/identity-cert type -1 debug1: identity file /home/thinkwrap/.ssh/id_rsa type 1 debug1: identity file /home/thinkwrap/.ssh/id_rsa-cert type -1 debug1: identity file /home/thinkwrap/.ssh/id_dsa type -1 debug1: identity file /home/thinkwrap/.ssh/id_dsa-cert type -1 debug1: Remote protocol version 2.0, remote software version OpenSSH_5.3 debug1: match: OpenSSH_5.3 pat OpenSSH* debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_5.3 debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: server->client aes128-ctr hmac-md5 none debug1: kex: client->server aes128-ctr hmac-md5 none debug1: SSH2_MSG_KEX_DH_GEX_REQUEST(1024<1024<8192) sent debug1: expecting SSH2_MSG_KEX_DH_GEX_GROUP debug1: SSH2_MSG_KEX_DH_GEX_INIT sent debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY debug1: Host 'pensieve.thinkwrap.com' is known and matches the RSA host key. debug1: Found key in /home/thinkwrap/.ssh/known_hosts:2 debug1: ssh_rsa_verify: signature correct debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: SSH2_MSG_SERVICE_REQUEST sent debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey,gssapi-keyex,gssapi-with-mic,password debug1: Next authentication method: gssapi-keyex debug1: No valid Key exchange context debug1: Next authentication method: gssapi-with-mic debug1: Unspecified GSS failure. Minor code may provide more information Credentials cache file '/tmp/krb5cc_500' not found debug1: Unspecified GSS failure. Minor code may provide more information Credentials cache file '/tmp/krb5cc_500' not found debug1: Unspecified GSS failure. Minor code may provide more information debug1: Unspecified GSS failure. Minor code may provide more information Credentials cache file '/tmp/krb5cc_500' not found debug1: Next authentication method: publickey debug1: Offering public key: /home/thinkwrap/.ssh/id_rsa debug1: Remote: Forced command: /home/thinkwrap/gitolite/src/gitolite-shell miro.adamy+ATG11-TrainingVM debug1: Remote: Port forwarding disabled. debug1: Remote: X11 forwarding disabled. debug1: Remote: Agent forwarding disabled. debug1: Remote: Pty allocation disabled. debug1: Server accepts key: pkalg ssh-rsa blen 277 Agent admitted failure to sign using the key. debug1: Trying private key: /home/thinkwrap/.ssh/identity debug1: Trying private key: /home/thinkwrap/.ssh/id_dsa debug1: Next authentication method: password thinkwrap@pensieve.thinkwrap.com's password: Solution # log-out, log on
After I created the ThinkWrap GitHub account and uploaded the public key, this key got somehow bound to GitHub identity ‘madamy’
I had to add user madamy to my public GitHub repo - where I keep the dot-files - https://github.com/radegast/dotvim
This may be an issue for people that have their own private accounts - the key management is the key.
This article is useful:
http://sealedabstract.com/code/github-ssh-with-multiple-identities-the-slightly-more-definitive-guide/ http://net.tutsplus.com/tutorials/tools-and-tips/how-to-work-with-github-and-multiple-accounts/ Alternative # Use https for forking , instead read/write ssh. No keys involved there
Issue # In dotvim repo, I used readonly URL for cloning the repository. Now I have created local branch ( linux-vm ) to track Linux specific font settings and need them to push up.
After creating new SSH pair and adding to GitHub, does not work
[tkuser@cplx-dev-vf .vim]$ git status # On branch linux-vm nothing to commit (working directory clean)[tkuser@cplx-dev-vf .vim]$ git push origin linux-vm fatal: remote error: You can't push to git://github.com/radegast/dotvim.git Use git@github.com:radegast/dotvim.git [tkuser@cplx-dev-vf .vim]$ git remote show origin * remote origin Fetch URL: git://github.com/radegast/dotvim.git Push URL: git://github.com/radegast/dotvim.git HEAD branch: master Remote branch: master tracked Local branch configured for 'git pull': master merges with remote master Local ref configured for 'git push': master pushes to master (up to date) [tkuser@cplx-dev-vf .vim]$ git remote set-url --push origin git@github.com:radegast/dotvim.git [tkuser@cplx-dev-vf .vim]$ git remote show origin * remote origin Fetch URL: git://github.com/radegast/dotvim.git Push URL: git@github.com:radegast/dotvim.git HEAD branch: master Remote branch: master tracked Local branch configured for 'git pull': master merges with remote master Local ref configured for 'git push': master pushes to master (up to date) [tkuser@cplx-dev-vf .vim]$ git push origin linux-vm Enter passphrase for key '/home/tkuser/.ssh/id_rsa': Counting objects: 5, done. Compressing objects: 100% (2/2), done. Writing objects: 100% (3/3), 306 bytes, done. Total 3 (delta 1), reused 0 (delta 0) To git@github.com:radegast/dotvim.git * [new branch] linux-vm -> linux-vm The important line is