{"thread":{"id":"20147","subject":"setup gitosis on Fedora 11","startedAt":"2009-07-17T21:45:14Z","lastAt":"2009-07-20T05:43:35Z","messageCount":7,"participants":["brizly vaan van Ulciputz","Sitaram Chamarty","Shakthi Kannan"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"118200","messageId":"1247867114.2384.15.camel@brizlyMobil","threadId":"20147","inReplyTo":null,"subject":"setup gitosis on Fedora 11","fromName":"brizly vaan van Ulciputz","fromEmail":"brizly@freenet.de","sentAt":"2009-07-17T21:45:14Z","receivedAt":"2009-07-17T21:45:14Z","isPatch":false,"sender":{"key":"brizly@freenet.de","avatar":null},"body":"Hello there,\n\ni tried to setup gitosis on a Fedora 11 system,\nsince i dont seem to be the only person having trouble here,\ni am asking here now.\n\nsomeone pasted that:\nhttp://paste.org/pastebin/view/9154\nand that's just the way i did it and the way i end in :-(\n\nwith the only difference i was using another 'tutorial'\nhttp://www.shakthimaan.com/installs/gitosis.html\n\ni tried a bit an sometimes ended in the prompt to enter password for\ngitosis@server after \"git push...\" No idea what to do.\n\nI asked #git and #fedora on freenode, was referred to this list.\nSo can anyone gimme a hint?\n\n_____\nluck up\nbrizly\n"},{"id":"118213","messageId":"2e24e5b90907171844o11eb6699m929e3c0df621ef67@mail.gmail.com","threadId":"20147","inReplyTo":"1247867114.2384.15.camel@brizlyMobil","subject":"Re: setup gitosis on Fedora 11","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2009-07-18T01:44:48Z","receivedAt":"2009-07-18T01:44:48Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Sat, Jul 18, 2009 at 3:15 AM, brizly vaan van\nUlciputz<brizly@freenet.de> wrote:\n\n> i tried to setup gitosis on a Fedora 11 system,\n> since i dont seem to be the only person having trouble here,\n> i am asking here now.\n>\n> someone pasted that:\n> http://paste.org/pastebin/view/9154\n> and that's just the way i did it and the way i end in :-(\n>\n> with the only difference i was using another 'tutorial'\n> http://www.shakthimaan.com/installs/gitosis.html\n>\n> i tried a bit an sometimes ended in the prompt to enter password for\n> gitosis@server after \"git push...\" No idea what to do.\n>\n> I asked #git and #fedora on freenode, was referred to this list.\n> So can anyone gimme a hint?\n\nline 12 in the first pastebin (and there's no need to use pastebins for a few\nlines on the mailing list; it's on #git that is really needed!) says\n    ERROR:gitosis.serve.main:Repository read access denied\n\nThis means you got past ssh issues, which is further along than most people\nwho come to #git with gitosis problems :-)\n\nThis error could mean one of the following:\n\n(1) you're using the wrong key/repo pair.  Of course your key *is* in\ngitosis.conf but the repo you're trying to push to isn't, or doesnot\nlist you as one of the valid users\n\n(2) your gitosis.conf is all correct, but you forgot the \"chmod\" somewhere\nabove, and the post-update hook never ran, so the real gitosis.conf (which\ngitosis uses -- this is ~git/.gitosis.conf) doesn't have the same data\n\nI also don't like that howto; it appears to be doing everything on one\nmachine, with the same userid, so people who don't grok ssh very well will\nstill have trouble even after all this is done to translate that knowledge to a\nreal deployment.\n\nBottom line: here's what should match for that error to go away:\n\n  - the public key corresponding to the private key your client-side ssh is\n    using\n  - must match *exactly* one of the public keys in the server-side\n    ~git/.ssh/authorized_keys\n\n[this is probably OK in your case, but please check there is *exactly one*.  I\nhave a vague memory of seeing a case when someone adds a key twice with\ndifferent usernames in error.  Ssh picks up perhaps the first one, while your\ngitosis.conf talks about the second one...]\n\nand\n\n  - the name after \"gitosis-init\" on the pubkey line that matched above\n  - must match a username in ~git/.gitosis.conf (which is a symlink to\n    something but never mind)\n\nand\n\n  - this username must be mentioned in the members= line of some section in\n    gitosis.conf which also has \"writable = my-first-repo\"\n\nYou can check *all* of this by looking at ~git/.gitosis.conf and\n~git/.ssh/authorized_keys on the server and ~/.ssh/id_[rd]sa.pub on your\nclient\n"},{"id":"118222","messageId":"1247902835.2384.86.camel@brizlyMobil","threadId":"20147","inReplyTo":"2e24e5b90907171844o11eb6699m929e3c0df621ef67@mail.gmail.com","subject":"Re: setup gitosis on Fedora 11","fromName":"brizly vaan van Ulciputz","fromEmail":"brizly@freenet.de","sentAt":"2009-07-18T07:40:35Z","receivedAt":"2009-07-18T07:40:35Z","isPatch":false,"sender":{"key":"brizly@freenet.de","avatar":null},"body":"i think it could be the think with post-update.\nBut because i don't know for sure how to set it up,\ni will at first try to be sure the other mentioned points are correct.\n\nbrizly2 is my notebook\ns28 is the server with gitosis\n\nSitaram Chamarty:\n> This error could mean one of the following:\n> \n> (1) you're using the wrong key/repo pair.  Of course your key *is* in\n> gitosis.conf but the repo you're trying to push to isn't, or doesnot\n> list you as one of the valid users\n\nto be sure i paste the md5 of the two keys:\n\n[brizly2@brizlyMobil ~]md5sum ~/.ssh/id_rsa.pub \nece497792a3cf840e55308f94b854efd  /home/brizly/.ssh/id_rsa.pub\n\n[root@s28 ~]# md5sum /home/brizly/.ssh/id_rsa.pub\nece497792a3cf840e55308f94b854efd  /home/brizly/.ssh/id_rsa.pub\n\ncomment: gitosis uses the same key as me as admin. isn't a problem, is\nit? The user brizly exists on notebook as on s2\n\n> (2) your gitosis.conf is all correct, but you forgot the \"chmod\" somewhere\n> above, and the post-update hook never ran, so the real gitosis.conf (which\n> gitosis uses -- this is ~git/.gitosis.conf) doesn't have the same data\n\nas mentioned above i don't know exactly where to set up the thing with\nthe post-update. And i actually don't have a git-user on the server (i\nhad one, but thought i didn't need one, so deleted it).\n\n> I also don't like that howto; it appears to be doing everything on one\n> machine, with the same userid, so people who don't grok ssh very well will\n> still have trouble even after all this is done to translate that knowledge to a\n> real deployment.\n\nBecause my first run wasn't very successfull, i tried another tutorial\nwhere the developer-machine and the gitosis-server are 2 different ones.\nsee http://www.shakthimaan.com/installs/gitosis.html\n\n> Bottom line: here's what should match for that error to go away:\n> \n>   - the public key corresponding to the private key your client-side ssh is\n>     using\n>   - must match *exactly* one of the public keys in the server-side\n>     ~git/.ssh/authorized_keys\n\nsee md5sums above, i think they are the same.\n\n> [this is probably OK in your case, but please check there is *exactly one*.  I\n> have a vague memory of seeing a case when someone adds a key twice with\n> different usernames in error.  Ssh picks up perhaps the first one, while your\n> gitosis.conf talks about the second one...]\n\nSo it is a problem when by 'normal' user on the server uses the same key\nas gitosis does? The server is not only serving gitosis, an for other\nreasons the user \"brizly\" is, for perspective of ssh, the same on\nnotebook and on server.\n\n> and\n>   - the name after \"gitosis-init\" on the pubkey line that matched above\n>   - must match a username in ~git/.gitosis.conf (which is a symlink to\n>     something but never mind)\n\nHow do i check that?\n\n> and\n>   - this username must be mentioned in the members= line of some section in\n>     gitosis.conf which also has \"writable = my-first-repo\"\n\n> You can check *all* of this by looking at ~git/.gitosis.conf and\n> ~git/.ssh/authorized_keys on the server and ~/.ssh/id_[rd]sa.pub on your\n> client\n\nby all my tries i know restarted end end up in again beeing prompted for\ngitosis-password:\n\n[root@s28 gitosis]# sudo -H -u gitosis gitosis-init\n< /home/brizly/.ssh/id_rsa.pub \nReinitialized existing Git repository\nin /var/lib/gitosis/repositories/gitosis-admin.git/\nReinitialized existing Git repository\nin /var/lib/gitosis/repositories/gitosis-admin.git/\n[root@s28 gitosis]# su - gitosis\n-sh-4.0$ pwd\n/var/lib/gitosis\n-sh-4.0$ cat .gitosis.conf \n[gitosis]\n\n[group gitosis-admin]\nwritable = gitosis-admin\nmembers = gitosis@s28\n\n###\nand after that (same on notebook or s28)\n[brizly@s28 ~]$ git clone gitosis@192.168.23.27:gitosis-admin.git\nInitialized empty Git repository in /home/brizly/gitosis-admin/.git/\ngitosis@192.168.23.27's password:\n\n\nso, at the moment i am again at the end of ideas, but the post-update.\nHow to check that?\n\n_____\nluck up\nbrizly\n"},{"id":"118221","messageId":"1247903695.2384.88.camel@brizlyMobil","threadId":"20147","inReplyTo":"ed88cb980907171752j5c61b3dfvd07298ac436abe38@mail.gmail.com","subject":"Re: setup gitosis on Fedora 11","fromName":"brizly vaan van Ulciputz","fromEmail":"brizly@freenet.de","sentAt":"2009-07-18T07:54:55Z","receivedAt":"2009-07-18T07:54:55Z","isPatch":false,"sender":{"key":"brizly@freenet.de","avatar":null},"body":"\n> Have you manually included your key on the ~/.ssh/authorized_keys? It\n> will bypass gitosis control!\n\nno, the authorizes_keys-file does not exists on both system in \"brizly\"s\naccount.\n"},{"id":"118255","messageId":"2e24e5b90907181829j1bf832a3k1812aba498ea09cf@mail.gmail.com","threadId":"20147","inReplyTo":"1247902835.2384.86.camel@brizlyMobil","subject":"Re: setup gitosis on Fedora 11","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2009-07-19T01:29:57Z","receivedAt":"2009-07-19T01:29:57Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Sat, Jul 18, 2009 at 1:10 PM, brizly vaan van Ulciputz\n<brizly@freenet.de> wrote:\n>\n> i think it could be the think with post-update.\n> But because i don't know for sure how to set it up,\n\nIt was in the how to you mentioned.\n\n> comment: gitosis uses the same key as me as admin. isn't a problem, is\n> it? The user brizly exists on notebook as on s2\n\nBy \"gitosis uses...\" I presume you mean \"the userid on the server that is\nbeing used as the gitosis user\".  Should not matter, normally, but see below\n\n> > (2) your gitosis.conf is all correct, but you forgot the \"chmod\" somewhere\n> > above, and the post-update hook never ran, so the real gitosis.conf (which\n> > gitosis uses -- this is ~git/.gitosis.conf) doesn't have the same data\n>\n> as mentioned above i don't know exactly where to set up the thing with\n> the post-update. And i actually don't have a git-user on the server (i\n> had one, but thought i didn't need one, so deleted it).\n\nyou either follow howtos (good or bad) as closely as you can, or you\nunderstand enough about ssh to bypass it.  You are mixing these two\napproaches; sorry I can't really help you.\n\nLet me say this: gitosis requires far more ssh knowledge than git knowledge.\nI do not want use this list to teach ssh, more than bare minimum.  Anyway I\nhave written quite a lot of stuff at\nhttp://sitaramc.github.com/0-installing/9-gitosis-server-install.html that\nmight help you in understanding.\n\n> > I also don't like that howto; it appears to be doing everything on one\n> > machine, with the same userid, so people who don't grok ssh very well will\n> > still have trouble even after all this is done to translate that knowledge to a\n> > real deployment.\n>\n> Because my first run wasn't very successfull, i tried another tutorial\n> where the developer-machine and the gitosis-server are 2 different ones.\n> see http://www.shakthimaan.com/installs/gitosis.html\n>\n> > Bottom line: here's what should match for that error to go away:\n> >\n> >   - the public key corresponding to the private key your client-side ssh is\n> >     using\n> >   - must match *exactly* one of the public keys in the server-side\n> >     ~git/.ssh/authorized_keys\n>\n> see md5sums above, i think they are the same.\n\nYou compared id_rsa.pub on both sides; you did not even compare the file I\nmentioned here (authorized_keys).  Sorry.\n\nOne mistake I made is I used the wrong emphasis above.  \"*exactly* one\" should\nbe read \"exactly *one*\" meaning it should not match more than one entry in the\nauthorized_keys file.\n\nOh the below para clarifies my intent anyway...\n\n> > [this is probably OK in your case, but please check there is *exactly one*.  I\n> > have a vague memory of seeing a case when someone adds a key twice with\n> > different usernames in error.  Ssh picks up perhaps the first one, while your\n> > gitosis.conf talks about the second one...]\n\n> So it is a problem when by 'normal' user on the server uses the same key\n> as gitosis does? The server is not only serving gitosis, an for other\n> reasons the user \"brizly\" is, for perspective of ssh, the same on\n> notebook and on server.\n\nYes normally it is a problem.  I repeat: this is nothing to do with gitosis;\nit is ssh knowledge you need.\n\n> > and\n> >   - the name after \"gitosis-init\" on the pubkey line that matched above\n> >   - must match a username in ~git/.gitosis.conf (which is a symlink to\n> >     something but never mind)\n>\n> How do i check that?\n\nSince you did not even look in the file I asked you to look, I guess you would\nnot find it...\n\nSummary: gitosis does require you to know a fair bit about unix and ssh.  I'm\nsorry that most howtos pretend to whitewash all that.\n"},{"id":"118278","messageId":"1248066634.2384.97.camel@brizlyMobil","threadId":"20147","inReplyTo":"2e24e5b90907181829j1bf832a3k1812aba498ea09cf@mail.gmail.com","subject":"Re: setup gitosis on Fedora 11","fromName":"brizly vaan van Ulciputz","fromEmail":"brizly@freenet.de","sentAt":"2009-07-20T05:10:34Z","receivedAt":"2009-07-20T05:10:34Z","isPatch":false,"sender":{"key":"brizly@freenet.de","avatar":null},"body":"> you either follow howtos (good or bad) as closely as you can, or you\n> understand enough about ssh to bypass it.  You are mixing these two\n> approaches; sorry I can't really help you.\n> \n> Let me say this: gitosis requires far more ssh knowledge than git knowledge.\n> I do not want use this list to teach ssh, more than bare minimum.  Anyway I\n> have written quite a lot of stuff at\n> http://sitaramc.github.com/0-installing/9-gitosis-server-install.html that\n> might help you in understanding.\n\nTo make this long story short i will go into me, rework through my\nssh-setup i have in my little network and walk through your link\nmentioned above.\n\nThank you so far.\nI thouht i had enough knowledge about ssh, but seems it's just dangerous\nsmattering (in my neighborhood we call it \"gefaehrliches\nHalbwissen\") :-)\n\n_____\nluck up\nbrizly\n"},{"id":"118280","messageId":"d16b1c80907192243v6a2033cdr84eba41683c29403@mail.gmail.com","threadId":"20147","inReplyTo":"1247902835.2384.86.camel@brizlyMobil","subject":"Re: setup gitosis on Fedora 11","fromName":"Shakthi Kannan","fromEmail":"shakthimaan@gmail.com","sentAt":"2009-07-20T05:43:35Z","receivedAt":"2009-07-20T05:43:35Z","isPatch":false,"sender":{"key":"shakthimaan@gmail.com","avatar":null},"body":"Hi,\n\n--- On Sat, Jul 18, 2009 at 1:10 PM, brizly vaan van\nUlciputz<brizly@freenet.de> wrote:\n| brizly2 is my notebook\n| s28 is the server with gitosis\n|\n| The user brizly exists on notebook as on s2\n\\--\n\nAs per the gitosis documentation that I have tested, the local user\ndoes not have a HOME account on the gitosis remote server. I am not\nsure if specifying the SSH file as 'username@hostname' will make a\ndifference in this context, when you add the local user SSH key to\ngitosis-admin/keydir.\n\n---\n| Because my first run wasn't very successfull, i tried another tutorial\n| where the developer-machine and the gitosis-server are 2 different ones.\n| see http://www.shakthimaan.com/installs/gitosis.html\n\\--\n\nPlease ping me 'mbuf' on #git if you have any queries regarding the\ndocumentation.\n\nSK\n\n-- \nShakthi Kannan\nhttp://www.shakthimaan.com\n"}]}