git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH] gpg: add support for gpgsm

From
Carlos Martín Nieto <cmn@dwim.me>
Date
Mar 31, 2016, 16:08 UTC
Message-ID
<1459440486.2124.18.camel@dwim.me>
In-Reply-To
<xmqqa8ler6pu.fsf@gitster.mtv.corp.google.com>
On Thu, 2016-03-31 at 08:46 -0700, Junio C Hamano wrote:
Show 24 quoted lines
> Carlos Martín Nieto <cmn@dwim.me> writes:
> 
> > 
> > Detect the gpgsm block header and run this command instead of gpg.
> > On the signing side, ask gpgsm if it knows the signing key we're
> > trying
> > to use and fall back to gpg if it does not.
> > 
> > This lets the user more easily combine signing and verifying X509
> > and
> > PGP signatures without having to choose a default for a particular
> > repository that may need to be occasionally overridden.
> > 
> > Signed-off-by: Carlos Martín Nieto <cmn@dwim.me>
> > 
> > ---
> > 
> > Out there in the so-called "real world", companies like using X509
> > to
> > sign things. Currently you can set 'gpg.program' to gpgsm to get
> > gpg-compatible verification,...
> I notice that you had to add GPGSM_MESSAGE string constant; does the
> current code without any change really work correctly if you set
> 'gpg.program' to gpgsm and do nothing else?

It does work for verify-commit which is what I've been playing around with since it just sends the contents of the 'gpgsig' header field to the verification function.

I don't recall testing with verify-tag but there we might indeed have issues, since we parse the contents to see if we have the signature.

Show 13 quoted lines
> 
> > 
> > ... but if you're changing it to swap between
> > PGP and X509, it's an extra variable to keep in mind when working
> > with
> > signed commits and tags.
> > 
> > +gpgsm.program::
> > +	Use this custom program instead of "gpgsm" found on $PATH
> > when
> > +	making or verifying a gpsm signature. The program must
> > support the
> gpsm signature, or gpgsm signature?
Nice catch. Thanks.
  cmn
Previous: Jeff KingNext: Jeff King
Message 7 of 8 in “gpg: add support for gpgsm”
  1. gpg: add support for gpgsmCarlos Martín Nieto, Mar 31, 2016
  2. Jeff KingMar 31, 2016
  3. Carlos Martín NietoMar 31, 2016
  4. Junio C HamanoMar 31, 2016
  5. Junio C HamanoMar 31, 2016
  6. Jeff KingMar 31, 2016
  7. Carlos Martín NietoMar 31, 2016
  8. Jeff KingMar 31, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.