How Git Client and Server authentication works using SSH

Viewed 27

I am just wondering how Git Client authentication works using public/private keys.

Step 1:

Git client and Git Server both will have public and private key pairs.

Git Client Has - Client Public Key & Client Private Key
Git Server Has - Server Public Key & Server Private Key

Step 2:

Client Public Key is added to Git Server manually.

Git Client Has - Client Public Key & Client Private Key
Git Server Has - Server Public Key & Server Private Key & Client Public Key

Step 3:

  1. Git client tries to clone using SSH URL.
  2. A popup is asked to store known-host and once known-hosts gets updated
  3. Repo gets cloned.
Q1. How server is validating client?
Q2. How client is validating server?
Q3. As I explained below client can be valid in one or the other way, what about the server when the connection is happening for the first time and client don't have public key of server in known-hosts?
Q4. Here these keys are just used for authentication or they are also used for data encryption like cloning, committing, pulling, pushing, etc.

Find my understanding and lack of clarity below

Why the lack of clarity

I read many articles online I see authentication can be done in different ways. I also read there are different types of authentication. I am wondering how Git Client and Server SSH is doing authentication.

For example server can send an encrypted text using client public key and then send it as a challenge to client and client will decrypt it and send it back to server to validate., If expected text server will think client is valid.

In other way around client can send some text with data with private key and server can use public key to decrypt the text and can think the client is valid because only owner can encrypt data with private key.

Same thing can be done by the client to validate server, but on first connection client does not have the public key of the server. So, in first connection how client is validating server?

0 Answers
Related