{"thread":{"id":"32790","subject":"How to identify the users?","startedAt":"2013-01-31T05:52:32Z","lastAt":"2013-01-31T10:12:08Z","messageCount":7,"participants":["Scott Yan","Tomas Carnecky","Sitaram Chamarty","Andrew Ardill"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"208333","messageId":"CACkbei+Jby13B7rsEb3iLQM2ZSFDgrkgvrYC5M7u4yatppvLxA@mail.gmail.com","threadId":"32790","inReplyTo":null,"subject":"How to identify the users?","fromName":"Scott Yan","fromEmail":"scottyan19@gmail.com","sentAt":"2013-01-31T05:52:32Z","receivedAt":"2013-01-31T05:52:32Z","isPatch":false,"sender":{"key":"scottyan19@gmail.com","avatar":null},"body":"Hello everyone:\n\nThe user info of git client (user name and email) is set by the users\nthemselves, so , how to avoid userA pretend to be userB?\n\nGit server could authentication the user, but it do nothing about the\nuser info of commit message.\n\nFor example:\nThere are 20 people of my team, and everyone can push to the public\nrepository(git server),\nIf I found some backdoor code in my project, and the commit record\nshows it was committed by userA, so I ask userA: why do you do this?\nbut he told me: no, this is not my code, I have never committed such\nthing.  ----and yes, everyone could change his user info to userA very\neasily .\n\nso... what should I do to avoid such situations?\nThanks!\n"},{"id":"208334","messageId":"CACkbeiKR4aYxP6uWtPVCsOLmNfj6fqv48vHdQokuAogR2b_a_Q@mail.gmail.com","threadId":"32790","inReplyTo":"CAH5451nd81aHtaxqpkTeCNG0xpuPd8ptdxRcOgGHaYuN3Qb7WA@mail.gmail.com","subject":"Re: How to identify the users?","fromName":"Scott Yan","fromEmail":"scottyan19@gmail.com","sentAt":"2013-01-31T06:07:37Z","receivedAt":"2013-01-31T06:07:37Z","isPatch":false,"sender":{"key":"scottyan19@gmail.com","avatar":null},"body":"Thanks, Andrew.\n\nyou said:\n--have the server reject commits that have the 'committer' set to\nsomeone other then the  authenticated user\n\nbut I don't know how to do that?\nOur central repository is hosted by apache, and there are some\nusername and passwords saved by apache to authentication valid user,\nbut as I know,  there are no relation between the apache username and\nthe git client user ino (saved in .gitconfig), so can you describe\nsome detail?\n\nRegards,\nScott Yan\n\nOn Thu, Jan 31, 2013 at 1:56 PM, Andrew Ardill <andrew.ardill@gmail.com> wrote:\n>\n>\n>\n> On 31 January 2013 16:52, Scott Yan <scottyan19@gmail.com> wrote:\n>>\n>> The user info of git client (user name and email) is set by the users\n>> themselves, so , how to avoid userA pretend to be userB?\n>>\n>> Git server could authentication the user, but it do nothing about the\n>> user info of commit message.\n>\n>\n> The simplest thing is to have the server reject commits that have the\n> 'committer' set to someone other then the  authenticated user.\n>\n> Of course, there are potential workflows that this would cause problems for,\n> such as if you sync directly to another user's repository and then try and\n> push those to a central server.\n>\n> The most robust system would probably involve using signed tags to verify\n> what is being pushed, however I am not aware of any set-ups that have done\n> this yet.\n>\n> Regards,\n>\n> Andrew Ardill\n"},{"id":"208335","messageId":"1359612481-ner-5936@calvin","threadId":"32790","inReplyTo":"CACkbei+Jby13B7rsEb3iLQM2ZSFDgrkgvrYC5M7u4yatppvLxA@mail.gmail.com","subject":"Re: How to identify the users?","fromName":"Tomas Carnecky","fromEmail":"tomas.carnecky@gmail.com","sentAt":"2013-01-31T06:08:01Z","receivedAt":"2013-01-31T06:08:01Z","isPatch":false,"sender":{"key":"tomas.carnecky@gmail.com","avatar":null},"body":"On Thu, 31 Jan 2013 13:52:32 +0800, Scott Yan <scottyan19@gmail.com> wrote:\n> Hello everyone:\n> \n> The user info of git client (user name and email) is set by the users\n> themselves, so , how to avoid userA pretend to be userB?\n> \n> Git server could authentication the user, but it do nothing about the\n> user info of commit message.\n> \n> For example:\n> There are 20 people of my team, and everyone can push to the public\n> repository(git server),\n> If I found some backdoor code in my project, and the commit record\n> shows it was committed by userA, so I ask userA: why do you do this?\n> but he told me: no, this is not my code, I have never committed such\n> thing.  ----and yes, everyone could change his user info to userA very\n> easily .\n> \n> so... what should I do to avoid such situations?\n\ngitolite keeps a log of which SSH user pushed which commits. The smart-http\nbackend does the same if you have reflog enabled on the server (see the\nENVIRONMENT section in man git-http-backend). So unless someone can steal\nuserA's credentials (http password, ssh key) you'll be able to detect who it\nreally was.\n"},{"id":"208336","messageId":"510A0ACF.5060501@gmail.com","threadId":"32790","inReplyTo":"1359612481-ner-5936@calvin","subject":"Re: How to identify the users?","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2013-01-31T06:10:23Z","receivedAt":"2013-01-31T06:10:23Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On 01/31/2013 11:38 AM, Tomas Carnecky wrote:\n> On Thu, 31 Jan 2013 13:52:32 +0800, Scott Yan <scottyan19@gmail.com> wrote:\n>> Hello everyone:\n>>\n>> The user info of git client (user name and email) is set by the users\n>> themselves, so , how to avoid userA pretend to be userB?\n>>\n>> Git server could authentication the user, but it do nothing about the\n>> user info of commit message.\n>>\n>> For example:\n>> There are 20 people of my team, and everyone can push to the public\n>> repository(git server),\n>> If I found some backdoor code in my project, and the commit record\n>> shows it was committed by userA, so I ask userA: why do you do this?\n>> but he told me: no, this is not my code, I have never committed such\n>> thing.  ----and yes, everyone could change his user info to userA very\n>> easily .\n>>\n>> so... what should I do to avoid such situations?\n> \n> gitolite keeps a log of which SSH user pushed which commits. The smart-http\n> backend does the same if you have reflog enabled on the server (see the\n> ENVIRONMENT section in man git-http-backend). So unless someone can steal\n> userA's credentials (http password, ssh key) you'll be able to detect who it\n> really was.\n\nSee also my rant on this topic:\n\nhttps://github.com/sitaramc/gitolite/blob/master/src/VREF/EMAIL-CHECK#L37\n"},{"id":"208337","messageId":"CAH5451kaXQj3Qz0P_Ydd+BnXwiENvqGP8tg4hHOgU8i5J_x5Lg@mail.gmail.com","threadId":"32790","inReplyTo":"CACkbei+Jby13B7rsEb3iLQM2ZSFDgrkgvrYC5M7u4yatppvLxA@mail.gmail.com","subject":"Re: How to identify the users?","fromName":"Andrew Ardill","fromEmail":"andrew.ardill@gmail.com","sentAt":"2013-01-31T06:16:48Z","receivedAt":"2013-01-31T06:16:48Z","isPatch":false,"sender":{"key":"andrew.ardill@gmail.com","avatar":"https://gravatar.com/avatar/da14cb7c091dd44dc6c63a4d3361b149acaf25226dc78eb4131a17b93d9b0993?d=mp&s=160"},"body":"(resending previous response. Forgot to turn off HTML, and apprently\ngmail doesn't wrap lines automatically anymore?)\n\nOn 31 January 2013 16:52, Scott Yan <scottyan19@gmail.com> wrote:\n>\n> The user info of git client (user name and email) is set by the users\n> themselves, so , how to avoid userA pretend to be userB?\n>\n> Git server could authentication the user, but it do nothing about the\n> user info of commit message.\n\n\nThe simplest thing is to have the server reject commits that have the\n'committer' set to someone other then the  authenticated user.\n\nOf course, there are potential workflows that this would cause problems\nfor, such as if you sync directly to another user's repository and then try\nand push those to a central server.\n\nThe most robust system would probably involve using signed tags to\nverify what is being pushed, however I am not aware of any set-ups that\nhave done this yet.\n\nRegards,\n\nAndrew Ardill\n"},{"id":"208342","messageId":"CACkbei+_dJowH-odL+UCS3hQwOwFZ7B5_6sxw=ZZg1V4=upSKg@mail.gmail.com","threadId":"32790","inReplyTo":"510A0ACF.5060501@gmail.com","subject":"Re: How to identify the users?","fromName":"Scott Yan","fromEmail":"scottyan19@gmail.com","sentAt":"2013-01-31T06:53:03Z","receivedAt":"2013-01-31T06:53:03Z","isPatch":false,"sender":{"key":"scottyan19@gmail.com","avatar":null},"body":"Thanks to all.\n\nTomas:\nI can't find reflog setting of git-http-backend\ndoc(http://www.kernel.org/pub/software/scm/git/docs/git-http-backend.html),\nI tried this setting:\ngit config core.logAllRefUpdates true\n\nand after some test push, the output is as below:\n>git log -g master\ncommit d34e61baa28eabf46ba5e9f6a2feb24cc683ed39\nReflog: master@{0} (Scott Yan <scottyan19@gmail.com>)\nReflog message: push\nAuthor: Scott Yan <scottyan19@gmail.com>\nDate:   Thu Jan 31 14:19:30 2013 +0800\n\nthis log shows when pushed, but still can't tell Who, because the\nauthor info may be fake.\nI don't know if I made some mistake.\n\n\nSitaram:\n\nIt seems I must host my central repo on Gitolite first...\nI don't know Gitolite much, but you are right, maybe I should use\nGitolite as my git server.\nI'll find more documents about gitolite these days,\ncan you give me some suggestion which tutorial should I read?  Thanks!\nps: my OS is windows.\n\nRegards,\nScott Yan\n\nOn Thu, Jan 31, 2013 at 2:10 PM, Sitaram Chamarty <sitaramc@gmail.com> wrote:\n> On 01/31/2013 11:38 AM, Tomas Carnecky wrote:\n>> On Thu, 31 Jan 2013 13:52:32 +0800, Scott Yan <scottyan19@gmail.com> wrote:\n>>> Hello everyone:\n>>>\n>>> The user info of git client (user name and email) is set by the users\n>>> themselves, so , how to avoid userA pretend to be userB?\n>>>\n>>> Git server could authentication the user, but it do nothing about the\n>>> user info of commit message.\n>>>\n>>> For example:\n>>> There are 20 people of my team, and everyone can push to the public\n>>> repository(git server),\n>>> If I found some backdoor code in my project, and the commit record\n>>> shows it was committed by userA, so I ask userA: why do you do this?\n>>> but he told me: no, this is not my code, I have never committed such\n>>> thing.  ----and yes, everyone could change his user info to userA very\n>>> easily .\n>>>\n>>> so... what should I do to avoid such situations?\n>>\n>> gitolite keeps a log of which SSH user pushed which commits. The smart-http\n>> backend does the same if you have reflog enabled on the server (see the\n>> ENVIRONMENT section in man git-http-backend). So unless someone can steal\n>> userA's credentials (http password, ssh key) you'll be able to detect who it\n>> really was.\n>\n> See also my rant on this topic:\n>\n> https://github.com/sitaramc/gitolite/blob/master/src/VREF/EMAIL-CHECK#L37\n"},{"id":"208350","messageId":"510A4378.9010302@gmail.com","threadId":"32790","inReplyTo":"CACkbei+_dJowH-odL+UCS3hQwOwFZ7B5_6sxw=ZZg1V4=upSKg@mail.gmail.com","subject":"Re: How to identify the users?","fromName":"Sitaram Chamarty","fromEmail":"sitaramc@gmail.com","sentAt":"2013-01-31T10:12:08Z","receivedAt":"2013-01-31T10:12:08Z","isPatch":false,"sender":{"key":"sitaramc@gmail.com","avatar":"https://avatars.githubusercontent.com/u/43316?v=4"},"body":"On 01/31/2013 12:23 PM, Scott Yan wrote:\n\n> Sitaram:\n> \n> It seems I must host my central repo on Gitolite first...\n\nThere is no \"must\" but yes it is a decent solution and can, in\nprinciple, do the kind of checking you want if you set it up to do that.\n Please note that I don't use that mode and, as my rant would have\nindicated, I don't think it's a smart thing to do.\n\n> I don't know Gitolite much, but you are right, maybe I should use\n> Gitolite as my git server.\n> I'll find more documents about gitolite these days,\n> can you give me some suggestion which tutorial should I read?  Thanks!\n> ps: my OS is windows.\n\nTry\nhttp://therightstuff.de/CommentView,guid,b969ea4d-8d2c-42af-9806-de3631f4df68.aspx\n\nI normally don't mention blog posts (favouring instead the official\ndocumentation) but Windows is an exception.  Hence the link.\n\nGood luck.\n"}]}