{"thread":{"id":"35593","subject":"Preventing unsigned commit/merge/tag","startedAt":"2013-12-31T17:49:01Z","lastAt":"2013-12-31T19:27:37Z","messageCount":2,"participants":["shawn wilson","brian m. carlson"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"232545","messageId":"CAH_OBicyrd=H1uG+_5-Jz=gK0fLsPbKKhkypWDG5yNb0umnhiw@mail.gmail.com","threadId":"35593","inReplyTo":null,"subject":"Preventing unsigned commit/merge/tag","fromName":"shawn wilson","fromEmail":"ag4ve.us@gmail.com","sentAt":"2013-12-31T17:49:01Z","receivedAt":"2013-12-31T17:49:01Z","isPatch":false,"sender":{"key":"ag4ve.us@gmail.com","avatar":null},"body":"What's the best way of doing this? I'd prefer this be a pre hook on\nthe server that rejects and the user has to rebase and fix their\nstuff. Though, if there's some way to make it easier for users not to\nmess up (other than an alias for everything which I'll probably do\nanyway) that would be useful. Any ideas?\n"},{"id":"232546","messageId":"20131231192736.GI451338@vauxhall.crustytoothpaste.net","threadId":"35593","inReplyTo":"CAH_OBicyrd=H1uG+_5-Jz=gK0fLsPbKKhkypWDG5yNb0umnhiw@mail.gmail.com","subject":"Re: Preventing unsigned commit/merge/tag","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2013-12-31T19:27:37Z","receivedAt":"2013-12-31T19:27:37Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On Tue, Dec 31, 2013 at 12:49:01PM -0500, shawn wilson wrote:\n> What's the best way of doing this? I'd prefer this be a pre hook on\n> the server that rejects and the user has to rebase and fix their\n> stuff. Though, if there's some way to make it easier for users not to\n> mess up (other than an alias for everything which I'll probably do\n> anyway) that would be useful. Any ideas?\n\nI don't believe the sign-on-rebase stuff ever got picked up, so at the\nmoment this wouldn't be a good idea, since each and every commit would\nhave to be manually amended.  It seems it never made it from the list\ninto Junio's queue whatsoever.  And the always-sign code is only in pu\nat the moment.\n\nBut if you wanted to anyway, you could simply use a pre-receive hook and\nwalk the tree, verifying the signatures of each commit against some\ncanonical list of approved keys.\n\n-- \nbrian m. carlson / brian with sandals: Houston, Texas, US\n+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only\nOpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187\n"}]}