{"thread":{"id":"17267","subject":"Few Questions","startedAt":"2009-01-20T10:38:49Z","lastAt":"2009-01-21T11:08:43Z","messageCount":5,"participants":["Arya, Manish Kumar","Matthieu Moy","Jakub Narebski","Shawn O. Pearce","R. Tyler Ballance"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"101246","messageId":"726600.29783.qm@web35708.mail.mud.yahoo.com","threadId":"17267","inReplyTo":null,"subject":"Few Questions","fromName":"Arya, Manish Kumar","fromEmail":"m.arya@yahoo.com","sentAt":"2009-01-20T10:38:49Z","receivedAt":"2009-01-20T10:38:49Z","isPatch":false,"sender":{"key":"m.arya@yahoo.com","avatar":null},"body":"Hi,\n\n   I am new to Git. Earlier I have configured svn with LDAP auth and svnwebclient.\n\nI want to have following with Git\n\n- LDAP and ssh authentication.\n\n- checkin and checkout using web interface and ssh\n\n- when ever someone checkin something then a email should be send to a email address (a mailing list)\n\nplease let me know how to do this with Git\n\n-Manish \n\n\n      \n"},{"id":"101247","messageId":"vpqljt6jl1p.fsf@bauges.imag.fr","threadId":"17267","inReplyTo":"726600.29783.qm@web35708.mail.mud.yahoo.com","subject":"Re: Few Questions","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@imag.fr","sentAt":"2009-01-20T11:04:18Z","receivedAt":"2009-01-20T11:04:18Z","isPatch":false,"sender":{"key":"git@matthieu-moy.fr","avatar":"https://avatars.githubusercontent.com/u/14709?v=4"},"body":"\"Arya, Manish Kumar\" <m.arya@yahoo.com> writes:\n\n> Hi,\n>\n>    I am new to Git. Earlier I have configured svn with LDAP auth and svnwebclient.\n>\n> I want to have following with Git\n>\n> - LDAP and ssh authentication.\n\nAFAIK, there isn't any authentication mechanism built into Git.\nInstead, Git relies on existing (proven, reliable, ...) mechanisms.\nSSH authentication is what you get when accessing a repository with\ne.g. git clone ssh://host.com/path/to/repo (either you have a full\nssh shell access on the server, or you can restrict the access with\ngit-shell to allow only basic git operations on the server).\n\nThere's probably a way to let your server use LDAP for authentication\nwhen using SSH, but that's independant from Git (and I'm helpless\nhere).\n\n> - checkin and checkout using web interface and ssh\n\nGitweb for the web interface. \"checkin\" and \"checkout\" have different\nmeanings depending on the tool, so I'm not sure I understand the\nquestion correctly.\n\nIn Git, the equivalent of \"checkout\" for centralized VCS would be\n\"clone\" (i.e. get a local working tree for a remote repository, but\nGit also duplicates the history), see above, it works straigtforwardly\nthrough SSH. I don't think you can do it from a web interface, but I\ndon't understand what would be the point in doing it.\n\n> - when ever someone checkin something then a email should be send to\n> a email address (a mailing list)\n\nWith a hook. You probably don't want to have this as the commit hook,\nsince the advantage of Git is to make \"commit\" a local, somehow\nprivate operation, and to distinguish it from \"push\" (which somehow\nmeans \"publish\", \"show to the rest of the world\"). So sending email\nwhen some server receives the new revisions is sensible, this is the\npost-receive hook.\n\nThese can help:\n\nhttp://git.kernel.org/?p=git/git.git;a=blob;f=contrib/hooks/post-receive-email;h=28a3c0e46ecf9951f3f42a025a288a65c70e0424;hb=HEAD\nhttp://source.winehq.org/git/tools.git/?a=blob;f=git-notify;hb=HEAD\n\n-- \nMatthieu\n"},{"id":"101259","messageId":"m3r62yx9qi.fsf@localhost.localdomain","threadId":"17267","inReplyTo":"726600.29783.qm@web35708.mail.mud.yahoo.com","subject":"Re: Few Questions","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2009-01-20T15:44:27Z","receivedAt":"2009-01-20T15:44:27Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"\"Arya, Manish Kumar\" <m.arya@yahoo.com> writes:\n\n> Hi,\n> \n> I am new to Git. Earlier I have configured svn with LDAP auth and\n> svnwebclient.\n> \n> I want to have following with Git\n> \n> - LDAP and ssh authentication.\n> \n\nInstead of inventing (and failing) its own protocol and its own\nauthentication git uses established solutions for authentication: SSH\nfor \"smart\" server, and WebDAV for push via (currently only \"dumb\")\nHTTPS protocol.\n\nThere exist solutions that help with setting up SSH for git:\ngit-shell, ssh_acl, and I think most commonly used Gitosis (see\nseminal reference about Gitosis on http://git.or.cz/gitwiki/BlogPosts).\n\n> - checkin and checkout using web interface and ssh\n> \n\nGit is distributed version control system: checkin (named 'commit' in\ngit) and checkout are _local_ operations.  Fetch (getting new changes\nfrom remote repository) and clone (creating new local repository\nfollowing or forking specified remote repository) can be done via\nlocal filesystem, via git:// protocol, via \"dumb\" HTTP, and via SSH.\nPush (sending changes to remote repository) needs autheticated\nchannel: most common used is SSH, but you can also use WebDAV with\nHTTPS.\n\nThere are web interfaces for Git, something like SVN::Web or ViewVC,\nlike gitweb (in Perl, developed in git.git repository) and cgit (in C).\nSee also \"Web interfaces\" section on InterfacesFrontendsAndTools page\non git wiki.\n\n> - when ever someone checkin something then a email should be send to\n>   a email address (a mailing list)\n\nIf by 'checkin' you mean publishing changes to a server (i.e. push in\ngit terminology), see for example contrib/hooks/post-receive-email\nhook.\n \n> please let me know how to do this with Git\n\nPlease learn that Git is _different_ from Subversion, and not try to\nfollow your SVN workflow and expectations blindly.\n\n-- \nJakub Narebski\nPoland\nShadeHawk on #git\n"},{"id":"101262","messageId":"20090120160410.GI14053@spearce.org","threadId":"17267","inReplyTo":"m3r62yx9qi.fsf@localhost.localdomain","subject":"Re: Few Questions","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2009-01-20T16:04:10Z","receivedAt":"2009-01-20T16:04:10Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Jakub Narebski <jnareb@gmail.com> wrote:\n> \"Arya, Manish Kumar\" <m.arya@yahoo.com> writes:\n> > \n> > I want to have following with Git\n> > \n> > - LDAP and ssh authentication.\n> > \n> \n> Instead of inventing (and failing) its own protocol and its own\n> authentication git uses established solutions for authentication: SSH\n> for \"smart\" server, and WebDAV for push via (currently only \"dumb\")\n> HTTPS protocol.\n> \n> There exist solutions that help with setting up SSH for git:\n> git-shell, ssh_acl, and I think most commonly used Gitosis (see\n> seminal reference about Gitosis on http://git.or.cz/gitwiki/BlogPosts).\n \nYup.  Gitosis is very popular for this.\n\nAt my last job I rolled my own Gitosis-lite, but in Perl, because\nthey are a Perl based shop.  It also uses the update-paranoid hook\nfor access controls, as its more flexible (and easier to confuse\nthe heck out of yourself) than Gitosis.  But if you can get along\nwith Gitosis, its a good choice.  Unfortunately its authentication\nis limited to public keys registered in the authorized keys file\nof the \"git\" user.\n\n<plug type=\"not-quite-ready-but-will-be-soon\">\n\nGerrit2 is also likely to enter this \"market\" soon.  I'm trying to\nget it production ready and live for one major project before the\nend of this month.  It embeds its own SSH daemon on a non-standard\nport, completely disconnected from the OS authentication.  This may\nmake it slightly more palatable in some enviroments then Gitosis,\nas you don't need a huge authorized_keys file, and you don't have\nto worry quite so much about attack vectors.\n\nUnlike with Gitosis, public key management is placed on end-users\nby using web authentication to identify the user, and letting the\nuser manage their own \"authorized key list\".  It also has a full\nblown web based code review system built in.  Which right now a\nproject must use if it is hosted by Gerrit2.  :-)\n\n</plug>\n\n-- \nShawn.\n"},{"id":"101372","messageId":"1232536123.3477.638.camel@starfruit","threadId":"17267","inReplyTo":"20090120160410.GI14053@spearce.org","subject":"Re: Few Questions","fromName":"R. Tyler Ballance","fromEmail":"tyler@slide.com","sentAt":"2009-01-21T11:08:43Z","receivedAt":"2009-01-21T11:08:43Z","isPatch":false,"sender":{"key":"tyler@slide.com","avatar":null},"body":"On Tue, 2009-01-20 at 08:04 -0800, Shawn O. Pearce wrote:\n> <plug type=\"not-quite-ready-but-will-be-soon\">\n> \n> Gerrit2 is also likely to enter this \"market\" soon.  I'm trying to\n> get it production ready and live for one major project before the\n> end of this month.  It embeds its own SSH daemon on a non-standard\n> port, completely disconnected from the OS authentication.  This may\n> make it slightly more palatable in some enviroments then Gitosis,\n> as you don't need a huge authorized_keys file, and you don't have\n> to worry quite so much about attack vectors.\n\n> </plug>\n> \n\n<plug type=\"not-really-existent-yet-but-gee-golly-i-wish-it-were\"\nvariant=\"mildly-offtopic\" unnecessary:attribute=\"is-unnecessary\">\n\nI talked with Chris Wanstrath (defunkt) of Git Hub once upon a time\nabout them open sourcing their additions onto the openSSH sshd(8) to\nwork public key lookup into a MySQL database instead of simply reading a\nflat file. \n\nIt'd be nice to add some peer pressure to get them to release it\nalready ;)\n\n</plug>\n\nI read your thread(s) on groups.google.com regarding Gerrit2 and it\nseems quite promising as well. Looking forward to it being ready ;)\n\nCheers\n-- \n-R. Tyler Ballance\nSlide, Inc.\n"}]}