{"thread":{"id":"29565","subject":"User authentication in GIT","startedAt":"2012-02-07T06:12:09Z","lastAt":"2012-02-13T18:19:38Z","messageCount":13,"participants":["supadhyay","Robin H. Johnson","Jakub Narebski","compufreak","Johan Herland","Sitaram Chamarty"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"184099","messageId":"1328595129258-7261349.post@n2.nabble.com","threadId":"29565","inReplyTo":null,"subject":"User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-07T06:12:09Z","receivedAt":"2012-02-07T06:12:09Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Hi All,\n\nI want to migrate my existing version control system (CVS) into GIT. The\nfirst question which comes to me is in CVS we have user authentication like\nusername and their password while in GIT there is SSH authentication. \n\nCan any one suggest me what is the optimal way to manage the users in GIT?\nDoes all users having username,passowrd and SSH key? or thre is no users\ncredential but only SSH authentication? if I have 1000 users in old system\nCVS then do I need to create a key for all 1000 users in GIT? or etc.\n\n\nThanks in advance...\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7261349.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"184104","messageId":"robbat2-20120207T072254-822967708Z@orbis-terrarum.net","threadId":"29565","inReplyTo":"1328595129258-7261349.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Robin H. Johnson","fromEmail":"robbat2@gentoo.org","sentAt":"2012-02-07T07:30:07Z","receivedAt":"2012-02-07T07:30:07Z","isPatch":false,"sender":{"key":"robbat2@gentoo.org","avatar":"https://avatars.githubusercontent.com/u/373898?v=4"},"body":"On Mon, Feb 06, 2012 at 10:12:09PM -0800,  supadhyay wrote:\n> Hi All,\n[snip]\n\n1. Go and use gitolite.\n2. All users must have their own SSH key. You do not create keys for them.\n\n-- \nRobin Hugh Johnson\nGentoo Linux: Developer, Trustee & Infrastructure Lead\nE-Mail     : robbat2@gentoo.org\nGnuPG FP   : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85\n"},{"id":"184112","messageId":"m3aa4vknwv.fsf@localhost.localdomain","threadId":"29565","inReplyTo":"1328595129258-7261349.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Jakub Narebski","fromEmail":"jnareb@gmail.com","sentAt":"2012-02-07T09:12:21Z","receivedAt":"2012-02-07T09:12:21Z","isPatch":false,"sender":{"key":"jnareb@gmail.com","avatar":"https://avatars.githubusercontent.com/u/2706?v=4"},"body":"supadhyay <supadhyay@imany.com> writes:\n\n> I want to migrate my existing version control system (CVS) into GIT. The\n> first question which comes to me is in CVS we have user authentication like\n> username and their password while in GIT there is SSH authentication. \n\nDo you use _unencrypted_ pserver, or tunelling over SSH (with CVS_RSH)?\n \n> Can any one suggest me what is the optimal way to manage the users in GIT?\n> Does all users having username, passoword and SSH key? or there is no users\n> credential but only SSH authentication? if I have 1000 users in old system\n> CVS then do I need to create a key for all 1000 users in GIT? or etc.\n\nFirst, Git supports unauthenticated anonymous fetching via custom\ngit:// protocol and via HTTP.  If you only need read-only access to\nrepository, it would be enough.  No account or SSH key necessary.\n\nSecond, Git uses SSH for authenthication instead of hand-rolling its\nown security system, badly.  You don't need to create 1000 shell\naccounts for SSH access: use tool like gitolite to manage git\nrepositories, which uses public-key infrastructure without need to\ngenerate 1000 accounts.  You would still need for each user to\ngenerate their own SSH key.\n\nSee gitolite documentation for more detail (older gitosis tool is no\nlonger maintained, as far as I know).\n\nHTH\n-- \nJakub Narebski\n"},{"id":"184117","messageId":"1328615262741-7262113.post@n2.nabble.com","threadId":"29565","inReplyTo":"1328595129258-7261349.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-07T11:47:42Z","receivedAt":"2012-02-07T11:47:42Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Hi Robin and Jakub,\n\nThanks for your reply. But I am still not getting what exactly I need to\nperform on GIT server. Please find my reply on your suggestion below:\n\n\nRobin:\nAll users must have their own SSH key. You do not create keys for them. \nMy rely: can you please give some more idea about how it works.. I am not\ngetting this or if you can provide any link for this to understand.\n\n\nJakub:\nMy reply: existing version control system used  pserver protocol.\n\nYou would still need for each user to generate their own SSH key.  \nMy reply: Do I need to store all end users sSH key in .ssh/authorized_keys\nfile on GIT server?\n\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7262113.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"184119","messageId":"CAO54GHA0Usa7D=m012gnObXYpdTVTjeeZUp47xnCJ7cDaJqTqg@mail.gmail.com","threadId":"29565","inReplyTo":"1328615262741-7262113.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"compufreak","fromEmail":"compufreak@gmail.com","sentAt":"2012-02-07T12:31:19Z","receivedAt":"2012-02-07T12:31:19Z","isPatch":false,"sender":{"key":"compufreak@gmail.com","avatar":"https://gravatar.com/avatar/10ca3ab6beccce3bbb196f655727a5ece331d2c95062270ef9d52e64f0d9356b?d=mp&s=160"},"body":"Inline respon\n\nOn Tue, Feb 7, 2012 at 12:47 PM, supadhyay <supadhyay@imany.com> wrote:\n> Hi Robin and Jakub,\n> ...\n> Robin:\n> All users must have their own SSH key. You do not create keys for them.\n> My rely: can you please give some more idea about how it works.. I am not\n> getting this or if you can provide any link for this to understand.\n\nSSH authentication can use private/public keys. The user generates a\nkeypair on their computer and gives you their public key, the private\nkey stays on their computer.\n>\n> Jakub:\n> My reply: existing version control system used  pserver protocol.\n>\n> You would still need for each user to generate their own SSH key.\n> My reply: Do I need to store all end users sSH key in .ssh/authorized_keys\n> file on GIT server?\n\nIf you were to do it manually, yes. But if you use gitolite [1], then\nyou add them to another git repository which handles everything for\nyou.\n\n> --\n> View this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7262113.html\n> Sent from the git mailing list archive at Nabble.com.\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n\n[1]: https://github.com/sitaramc/gitolite\n"},{"id":"184120","messageId":"CALKQrgdvOhfhTPg+g+LqCb6XOQczcz-nYC61B9x4W5dB4Up5oA@mail.gmail.com","threadId":"29565","inReplyTo":"1328615262741-7262113.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Johan Herland","fromEmail":"johan@herland.net","sentAt":"2012-02-07T12:32:35Z","receivedAt":"2012-02-07T12:32:35Z","isPatch":false,"sender":{"key":"johan@herland.net","avatar":"https://avatars.githubusercontent.com/u/547031?v=4"},"body":"On Tue, Feb 7, 2012 at 12:47, supadhyay <supadhyay@imany.com> wrote:\n> Hi Robin and Jakub,\n>\n> Thanks for your reply. But I am still not getting what exactly I need to\n> perform on GIT server. Please find my reply on your suggestion below:\n>\n>\n> Robin:\n> All users must have their own SSH key. You do not create keys for them.\n> My rely: can you please give some more idea about how it works.. I am not\n> getting this or if you can provide any link for this to understand.\n\n- Each user generates their own ssh key pair on their own workstation\n(in openssh, the command for generating a new key is called\n'ssh-keygen')\n\n- Each user then sends their public key to you (using email or\nwhatever communication form is easiest for you).\n\n- You then load the keys into gitolite (by copying them into your\nlocal clone of the gitolite-admin repo, committing, and pushing to the\ngitolite-admin repo to the server).\n\nMore details here: http://sitaramc.github.com/gitolite/add.html (and\nin associated documentation)\n\n> Jakub:\n> My reply: existing version control system used  pserver protocol.\n>\n> You would still need for each user to generate their own SSH key.\n> My reply: Do I need to store all end users sSH key in .ssh/authorized_keys\n> file on GIT server?\n\nNo. You load them into gitolite (as described above, and in gitolite's\ndocumentation), and then gitolite takes care of managing them.\n\n\nHave fun! :)\n\n...Johan\n\n-- \nJohan Herland, <johan@herland.net>\nwww.herland.net\n"},{"id":"184136","messageId":"1328632848471-7262934.post@n2.nabble.com","threadId":"29565","inReplyTo":"CALKQrgdvOhfhTPg+g+LqCb6XOQczcz-nYC61B9x4W5dB4Up5oA@mail.gmail.com","subject":"Re: User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-07T16:40:48Z","receivedAt":"2012-02-07T16:40:48Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Thank you Johan,freak.\n\nyou have clear my doubts at some extent and I think let me work on it.\n\nI will work on giloite and get back to you.\n\nThanks...\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7262934.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"184149","messageId":"CAMK1S_i=QUxf1CPDwdDn0+2-7fL5xxMZ67rHvR63a-vU1uq39Q@mail.gmail.com","threadId":"29565","inReplyTo":"1328632848471-7262934.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2012-02-07T18:26:59Z","receivedAt":"2012-02-07T18:26:59Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Tue, Feb 7, 2012 at 10:10 PM, supadhyay <supadhyay@imany.com> wrote:\n> Thank you Johan,freak.\n>\n> you have clear my doubts at some extent and I think let me work on it.\n>\n> I will work on giloite and get back to you.\n\nI've also been working on some nice pictures... maybe they will help,\nwho knows...\n\nhttp://sitaramc.github.com/gitolite/pictures.html\n"},{"id":"184364","messageId":"1328893056653-7273350.post@n2.nabble.com","threadId":"29565","inReplyTo":"CAMK1S_i=QUxf1CPDwdDn0+2-7fL5xxMZ67rHvR63a-vU1uq39Q@mail.gmail.com","subject":"Re: User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-10T16:57:36Z","receivedAt":"2012-02-10T16:57:36Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Hi Sitaram,\n\nThanks for helping me by providing such a good link. Now, I am able to\nunderstand how to manage the user in efficient way.\n\nWith that I have one question is-  in my GIT server we already migrated our\nsource code (pilot testing) from CVS to GIT. We used user \"GITAdmin\" for\nmigration and though its for pilot testing only we use the home directory\nfor source code repository is /home/GITAdmin/migration/VVD.git.\n\nnow the question is, I install gitolie using the same user \"GITAdmin\" and on\nthe same path i.e. /home/GITAdmin. And when add repository from my\nworkstation (git add conf/glitolite.conf) , this added repositories\ndirectory on the GIT server path /home/GITAdmin/repositories/MRB.git\n\nNow my confusion is my existing source code repository directory path during\nmigration /home/GITAdmin/migration/<repository.git> and now through gitolite\nI want to manage both users and repositories  but through gitolite it add\nrepository in different path /home/GITAdmin/repositories/<repository.git>.\n\n\nCan you please help how through gitolite I can add new repository on to the\nsame my exisitng migrated repository directory?\n\n\n\n\nThanks,\nSuchi\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7273350.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"184426","messageId":"CAMK1S_gOhaX4SaUZk8RrByDa_HPuMLDs=T2M2djXDhvESJu1Vg@mail.gmail.com","threadId":"29565","inReplyTo":"1328893056653-7273350.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2012-02-11T05:17:02Z","receivedAt":"2012-02-11T05:17:02Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Fri, Feb 10, 2012 at 10:27 PM, supadhyay <supadhyay@imany.com> wrote:\n\n> Now my confusion is my existing source code repository directory path during\n> migration /home/GITAdmin/migration/<repository.git> and now through gitolite\n> I want to manage both users and repositories  but through gitolite it add\n> repository in different path /home/GITAdmin/repositories/<repository.git>.\n>\n>\n> Can you please help how through gitolite I can add new repository on to the\n> same my exisitng migrated repository directory?\n\ngitolite keeps all its repos in whatever directory is pointed to by\n$REPO_BASE in the rc file.  This is $HOME/repositories by default but\nyou can change it to whatever you want.  Instructions for changing it\nare in the 4th bullet of\nhttp://sitaramc.github.com/gitolite/rc.html#gitolite_rc_rarely_changed_variables_\n\nIf you are moving existing repos into gitolite, be sure to read\nhttp://sitaramc.github.com/gitolite/moverepos.html -- if you do it\nwrong you may end up without the crucial \"update\" hook and then all\naccess control will fail.\n"},{"id":"184564","messageId":"1329137674044-7280277.post@n2.nabble.com","threadId":"29565","inReplyTo":"CAMK1S_gOhaX4SaUZk8RrByDa_HPuMLDs=T2M2djXDhvESJu1Vg@mail.gmail.com","subject":"Re: User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-13T12:54:34Z","receivedAt":"2012-02-13T12:54:34Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Thanks Sitaram for your reply and guidance.\n\n>From your document I can see there are three different method to install\ngitolite. May I know all methods advantage and disadvantage?\n\nThanks,\nSuchi\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7280277.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"184566","messageId":"CAMK1S_g5mk44vhTsFG4-kzMw7jMVvX0VK6pXAY=PFAgOEsccgw@mail.gmail.com","threadId":"29565","inReplyTo":"1329137674044-7280277.post@n2.nabble.com","subject":"Re: User authentication in GIT","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2012-02-13T14:32:34Z","receivedAt":"2012-02-13T14:32:34Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On Mon, Feb 13, 2012 at 6:24 PM, supadhyay <supadhyay@imany.com> wrote:\n> Thanks Sitaram for your reply and guidance.\n>\n> From your document I can see there are three different method to install\n> gitolite. May I know all methods advantage and disadvantage?\n\nsee first para after the 4 bullets in\nhttp://sitaramc.github.com/gitolite/install.html#install_installing_and_upgrading_gitolite_\n"},{"id":"184578","messageId":"1329157178665-7281349.post@n2.nabble.com","threadId":"29565","inReplyTo":"CAMK1S_g5mk44vhTsFG4-kzMw7jMVvX0VK6pXAY=PFAgOEsccgw@mail.gmail.com","subject":"Re: User authentication in GIT","fromName":"supadhyay","fromEmail":"supadhyay@imany.com","sentAt":"2012-02-13T18:19:38Z","receivedAt":"2012-02-13T18:19:38Z","isPatch":false,"sender":{"key":"supadhyay@imany.com","avatar":null},"body":"Thanks for suggesting the link, but would like to know which method is the\nmost secure and optimal method to use.\n\nFor testing purpose we migrate our repositories from CVS2GIT but now having\nissue wiht user managment. How to manage it ? We have users for different\nrepositories and having different access, somewhere I read about using\nGitolite I can mange users but not find the efficent and useful method to\nuse it.\n\n\n\nThanks .\n..\n\n\n--\nView this message in context: http://git.661346.n2.nabble.com/User-authentication-in-GIT-tp7261349p7281349.html\nSent from the git mailing list archive at Nabble.com.\n"}]}