git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [Q] Encrypted GIT?

From
Theodore Tso <tytso@mit.edu>
Date
Mar 13, 2008, 12:58 UTC
Message-ID
<20080313125853.GA12927@mit.edu>
In-Reply-To
<20080313121644.GD2414@genesis.frugalware.org>
On Thu, Mar 13, 2008 at 01:16:44PM +0100, Miklos Vajna wrote:
Show 8 quoted lines
> On Thu, Mar 13, 2008 at 12:55:11PM +0100, Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:
> > The latter can be remedied (somewhat) by encrypting each object 
> > individually.  In that case, .gitattributes can help (you should be able 
> > to find a mail to that extent, which I sent no more than 2 weeks ago).  
> > However, you must make sure that the encryption is repeatable, i.e. two 
> > different encryption runs _must_ result in _identical_ output.
> 
> afaik, this is not the case for gpg.

No, and you wouldn't want to use gpg because of the overhead it adds around an encrypted message. You would need to use a raw encryption algorithm, or one with very minimal wrapping. It's normally at this point that that you'd need to bring in a security expert to ask a whole lot of questions about your exact use scenario, do a formal threat analysis, since there are all sorts of unanswered questions about what kind of key management solution you really need for your situation.

It's usually not as simple as "just encrypt it". How many people need to have access to the to the repository? Do you need to revoke access to the repository later? Who is allowed to give a new person access to the repository? etc., etc., etc.

						- Ted
Previous: Miklos VajnaNext: Alexander Gladysh
Message 5 of 17 in “[Q] Encrypted GIT?”
  1. Alexander GladyshMar 13, 2008
  2. Miklos VajnaMar 13, 2008
  3. Johannes SchindelinMar 13, 2008
  4. Miklos VajnaMar 13, 2008
  5. Theodore TsoMar 13, 2008
  6. Alexander GladyshMar 13, 2008
  7. Johannes SchindelinMar 13, 2008
  8. Jeff KingMar 13, 2008
  9. Jeff KingMar 13, 2008
  10. Jeff KingMar 13, 2008
  11. Theodore TsoMar 13, 2008
  12. Jeff KingMar 13, 2008
  13. David BrownMar 13, 2008
  14. Thomas HarningMar 13, 2008
  15. Luke LuMar 13, 2008
  16. Thomas HarningMar 13, 2008
  17. Luke LuMar 13, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.