{"thread":{"id":"23428","subject":"simplest git deamon?","startedAt":"2010-04-12T13:47:40Z","lastAt":"2010-04-12T23:22:39Z","messageCount":5,"participants":["Mihamina Rakotomandimby","Shawn O. Pearce","Matthieu Moy","Tomas Carnecky","Ilari Liusvaara"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"139333","messageId":"20100412164740.740050cb@pbmiha.malagasy.com","threadId":"23428","inReplyTo":null,"subject":"simplest git deamon?","fromName":"Mihamina Rakotomandimby","fromEmail":"mihamina@gulfsat.mg","sentAt":"2010-04-12T13:47:40Z","receivedAt":"2010-04-12T13:47:40Z","isPatch":false,"sender":{"key":"mihamina@gulfsat.mg","avatar":null},"body":"Manao ahoana, Hello, Bonjour,\n\nI would like to setup a git repository, on a Debian machine.\nI would like to access it only with git:// (no http://, no ssh://,...)\n\nHow to implement read/write restriction when just wanting to use\n\"git://\" without dealing with SSH?\n\nhttp://www.kernel.org/pub/software/scm/git/docs/everyday.html, at it's\nbottom tlak about this but it requires SSH.\nhttps://help.ubuntu.com/community/Git talks about gitosis, but it\nrequires keys.\n\nI have the GIT repository setup, with the \"git://\"-only access scheme, \nbut anyone may push into this.\n\nI expected just a flat file the SVN way (But I dont want to use SVN):\n\n  [users]\n  alice: al_pass\n  bob  : b_pass\n  \n  [groups]\n  senior:alice,bob\n  \n  [permissions]\n  @senior:all\n  @anonymous:clone\n\nHow could I do that?\n\nMisaotra, Thanks, Merci.\n\n-- \n       Architecte Informatique chez Blueline/Gulfsat:\n    Administration Systeme, Recherche & Developpement\n                +261 34 29 155 34 / +261 33 11 207 36\n"},{"id":"139334","messageId":"20100412142203.GB6313@spearce.org","threadId":"23428","inReplyTo":"20100412164740.740050cb@pbmiha.malagasy.com","subject":"Re: simplest git deamon?","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2010-04-12T14:22:03Z","receivedAt":"2010-04-12T14:22:03Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Mihamina Rakotomandimby <mihamina@gulfsat.mg> wrote:\n> Manao ahoana, Hello, Bonjour,\n> \n> I would like to setup a git repository, on a Debian machine.\n> I would like to access it only with git:// (no http://, no ssh://,...)\n> \n> How to implement read/write restriction when just wanting to use\n> \"git://\" without dealing with SSH?\n> \n> http://www.kernel.org/pub/software/scm/git/docs/everyday.html, at it's\n> bottom tlak about this but it requires SSH.\n> https://help.ubuntu.com/community/Git talks about gitosis, but it\n> requires keys.\n> \n> I have the GIT repository setup, with the \"git://\"-only access scheme, \n> but anyone may push into this.\n> \n> I expected just a flat file the SVN way (But I dont want to use SVN):\n\nGit isn't SVN.\n\nThe git:// daemon is *anonymous*.  It has no authentication\ncapability, nor will it probably ever learn how to authenticate\nusers.  Consequently you can't do what you want with it.\n\nInstead of reinventing the wheel poorly, Git relies on external\nservers to perform the authentication.  So if you want authenticated\naccess, you will need to use either SSH or HTTP.\n\nIf you use SSH, lots of people get by with Gitosis, as its fairly\nsimple to configure.  Another option is to use something much more\ncomplex like Gerrit Code Review[1] that contains its own SSH server.\n\nIf you use HTTP, use the newer git-http-backend[2] that was\nintroduced in Git 1.6.6 (or later), running behind an Apache\nHTTP server.\n\n[1] http://code.google.com/p/gerrit/\n[2] http://www.kernel.org/pub/software/scm/git/docs/git-http-backend.html\n \n-- \nShawn.\n"},{"id":"139341","messageId":"4BC32CCF.5060303@dbservice.com","threadId":"23428","inReplyTo":"20100412164740.740050cb@pbmiha.malagasy.com","subject":"Re: simplest git deamon?","fromName":"Tomas Carnecky","fromEmail":"tom@dbservice.com","sentAt":"2010-04-12T14:23:11Z","receivedAt":"2010-04-12T14:23:11Z","isPatch":false,"sender":{"key":"tom@dbservice.com","avatar":"https://gravatar.com/avatar/900a300bdd1a8bbe086008ad78210bbee2ad2803b7d50a5cba04c1e9404bd6d2?d=mp&s=160"},"body":"On 4/12/10 3:47 PM, Mihamina Rakotomandimby wrote:\n> Manao ahoana, Hello, Bonjour,\n>\n> I would like to setup a git repository, on a Debian machine.\n> I would like to access it only with git:// (no http://, no ssh://,...)\n>\n> How to implement read/write restriction when just wanting to use\n> \"git://\" without dealing with SSH?\n\nThe git:// protocol is anonymous, not authenticated. If you want to \nallow read/write access to repositories while restricting access only to \ncertain users, you'll have to use http:// or ssh:// (with the later \nstrongly preferred). Try gitolite [1], it isn't that hard to set it up.\n\ntom\n\n[1] http://github.com/sitaramc/gitolite\n"},{"id":"139337","messageId":"vpqmxx8g34h.fsf@bauges.imag.fr","threadId":"23428","inReplyTo":"20100412164740.740050cb@pbmiha.malagasy.com","subject":"Re: simplest git deamon?","fromName":"Matthieu Moy","fromEmail":"matthieu.moy@grenoble-inp.fr","sentAt":"2010-04-12T14:24:46Z","receivedAt":"2010-04-12T14:24:46Z","isPatch":false,"sender":{"key":"matthieu.moy@grenoble-inp.fr","avatar":"https://gravatar.com/avatar/72c8a2705971a25dfaff23cece15130d405685845d911aedd5667ace277f3fc5?d=mp&s=160"},"body":"Mihamina Rakotomandimby <mihamina@gulfsat.mg> writes:\n\n> Manao ahoana, Hello, Bonjour,\n>\n> I would like to setup a git repository, on a Debian machine.\n> I would like to access it only with git:// (no http://, no ssh://,...)\n>\n> How to implement read/write restriction when just wanting to use\n> \"git://\" without dealing with SSH?\n\nYou do want SSH: Git itself doesn't do encryption, so implementing\naccess control over plain git:// would be insecure. And Git prefered\nto delegate access control to well established solution such as SSH.\n\nI'd recommand having a second look at gitosis, or its variant\ngitolite, which provide a configuration file mostly like what you\nexpect :\n\n>   [users]\n>   alice: al_pass\n>   bob  : b_pass\n>   \n>   [groups]\n>   senior:alice,bob\n>   \n>   [permissions]\n>   @senior:all\n>   @anonymous:clone\n\n-- \nMatthieu Moy\nhttp://www-verimag.imag.fr/~moy/\n"},{"id":"139375","messageId":"20100412232239.GA890@LK-Perkele-V2.elisa-laajakaista.fi","threadId":"23428","inReplyTo":"20100412164740.740050cb@pbmiha.malagasy.com","subject":"Re: simplest git deamon?","fromName":"Ilari Liusvaara","fromEmail":"ilari.liusvaara@elisanet.fi","sentAt":"2010-04-12T23:22:39Z","receivedAt":"2010-04-12T23:22:39Z","isPatch":false,"sender":{"key":"ilari.liusvaara@elisanet.fi","avatar":null},"body":"On Mon, Apr 12, 2010 at 04:47:40PM +0300, Mihamina Rakotomandimby wrote:\n> Manao ahoana, Hello, Bonjour,\n> \n> I would like to setup a git repository, on a Debian machine.\n> I would like to access it only with git:// (no http://, no ssh://,...)\n> \n> How to implement read/write restriction when just wanting to use\n> \"git://\" without dealing with SSH?\n\nYou can't. git:// in its base form does not support authentication.\n\nYes, one could extend git:// to support authentication and encryption\n(been there, done that), but that isn't usable as client end requires\nextra software not included in standard git install (that server end\nrequires extra software is comparatively no problem).\n\n-Ilari\n"}]}