Archived post — originally dated January 22, 2013.
Historical context: These notes describe a 2013 Windows workflow combining KeePass 2 and KeeAgent with PuTTY’s Pageant/Plink, Cygwin, and SparkleShare. This is not a current installation or security guide. Plugin compatibility, menus, installation paths, and SSH-agent integration may have changed; consult current official documentation before configuring a password manager or importing private keys. The original download links below use HTTP; use the official HTTPS sites when obtaining software.
Corrections to the historical instructions: The value
pinkbelow appears to be a typo forplink.GIT_SSHselects the SSH command used by Git; it does not configure OpenSSH itself to use Plink. Shell syntax and agent compatibility depend on the environment, so the old Cygwin bridge and SparkleShare steps should not be assumed necessary today.
To start using Keepass as a replacement for pageant you must do the following.
- Download KeePass
- Download KeeAgent
- Set up Keepass by creating a KeePass database, a password, and key file, if you don’t already have one.
- Install Keeagent to the
Program Files\KeePass Password Safe 2\PluginsDirectory and restart Keepass. - Add an existing private.ppk as an attachment and its encryption password in the password field to a new Keepass Entry. I also like to include the public key as a string field attachment.
- Test it out by going to
Tools -> KeeAgent -> List PuTTY Keys
Thats it! Now Keepass is ready to act as pageant! Now comes the real work. You still have to:
- Set up some environment variables so that Open-SSH uses
plinkinstead ofsshso thatpageantis used rather thanssh-agent.- This requires some understanding of the
$PATH - This also requires adding
plinkto your windows$PATH - You must also add
$GIT_SSHand set it to ‘pink’
- This requires some understanding of the
- Install
charadeas a bridge from Cygwin topageant. - Tweak Sparkleshare to use the system’s
$GIT_SSHvariable instead of its built in version ofssh.
I’ll be going over these different steps, as well as why you might want to take the time to do this kind of thing in subsequent posts. And always, if you know a better way of doing things, or I am making silly or dangerous mistakes, please email me.