{"thread":{"id":"12834","subject":"Committer authentication in git-send-pack/git-receive-pack","startedAt":"2008-03-24T04:01:56Z","lastAt":"2008-03-24T04:01:56Z","messageCount":1,"participants":["James Sadler"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"72853","messageId":"e5e204700803232101l431919e0ic8e9fb10c18867d2@mail.gmail.com","threadId":"12834","inReplyTo":null,"subject":"Committer authentication in git-send-pack/git-receive-pack","fromName":"James Sadler","fromEmail":"freshtonic@gmail.com","sentAt":"2008-03-24T04:01:56Z","receivedAt":"2008-03-24T04:01:56Z","isPatch":false,"sender":{"key":"freshtonic@gmail.com","avatar":"https://gravatar.com/avatar/b6650ce4e0ec8d7169a964ef15255a74205599a33a9cb8295a6018db566c2fdc?d=mp&s=160"},"body":"A while ago, there was some discussion about authenticating commits\nusing gnupg signatures.\n(see http://kerneltrap.org/mailarchive/git/2008/1/29/634209).\n\nI have searched through all of the branches in the main git repo and I\ncan't see any commits relating to this functionality, so I was\nwondering if the work had stalled or perhaps not even been started.\nIf that's the case, I'm willing to give it a shot and would welcome\nsome discussion on how to get started.\n\nThe posts in the aforementioned thread expand upon the concept beyond\nmere authentication and into full audit trail territory.  It sounds\nlike a significant chunk of work.\n\nHowever, the first logical step (at least to me!) would be to extend\ngit-send-pack and git-receive-pack to sign and verify communications.\n\ngit-send-pack could be extended with a '--sign' argument.  This should\nproduce a signature generated by passing the 'command' part of the\ngit-send-pack output through to gpg.  The rest of the pack need not be\nsigned, as the SHA-1s in the command section already are\ncryptographically associated with the pack itself.\n\nAt the  other end, git-receive-pack would need to be invoked in such a\nway that it knows only to accept signed communications, and where to\nfind a list of public keys that will be used to authenticate the data.\nIt will check that the committer's key is known and that the signature\nmatches the command section generated by send-pack.  If the\ncommunication is not signed, or committer is unknown or it fails\nverification for any reason, git-receive-pack should die with an\nappropriate message.\n\n>From this starting point, other features (discussed in aforementioned\nthread) could eventually be added.\n\nThoughts/advice/opinions/critique welcome.\n-- \nJames\n"}]}