From: Sean Date: Sat, 23 Apr 2005 18:14:57 GMT Subject: Re: Git-commits mailing list feed. Message-ID: <1242.10.10.10.24.1114280097.squirrel@linux1> In-Reply-To: <20050423190257.GA4194@cip.informatik.uni-erlangen.de> On Sat, April 23, 2005 3:02 pm, Thomas Glanzmann said: > Hello, > >> Why not leave tags open to being signed or unsigned? > > I think that this is the idea anyway. > >> For presentation in the log or whatever, the script can look inside the >> clear text message, grab the SHA1 and display it in the header area; >> even >> though it's not really in the header, always just in the clear text >> area. > > Having the SHA1 signature twice in would be confusing and error-prone > when checking is done automated. > > So establishing the infrastructure is a good thing. To use it for every > commit is another issue. There's no need to have the SHA1 object reference twice. It will only be in the clear text, nowhere else. Of course scripts that display the log, could show the object reference in the header area for aesthetics. Another nice thing is that this works no matter cleartext signing methods emerge in the future. Sean