git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] Adding a challenge-response authentication method to git://

From
Stephen R. van den Berg <srb@cuci.nl>
Date
Aug 13, 2008, 17:37 UTC
Message-ID
<20080813173757.GE12200@cuci.nl>
In-Reply-To
<20080813164038.GE3782@spearce.org>
Shawn O. Pearce wrote:
>"Stephen R. van den Berg" <srb@cuci.nl> wrote:
>> What are the opinions on adding a basic challenge-response type
>> authentication mechanism to the native git protocol?
>> SHA1 (surprise ;-) to actually encrypt username/password/salt
>Last time we talked about this we got off onto some tagent about
>using GnuPG public keys to authenticate users, and then how we might
...

That is the feature rich solution. For those there is ssh/webdav and possibly other setups.

>Isn't there some authentication frontend that some IMAP servers
>use to handle the authentication for them?  I think last time

There is GSSAPI, which allows plugging in just about anything you like. Nonetheless, for a lot of small projects, you have a relatively small number of developers (typically <32) which have commitrights on one or more source trees in a central repository.

In order to aid them in setting up a simple accesslist, git would do just fine by simply offering a flat-file like list. Forcing those setups to use anything more complicated makes adoption of git for those kind of projects unreasonably more complicated (IMO).

There are no promises for flexibility, security, whatsoever. The only things I'm aiming for are: a. Simplicity (need just git). b. No cleartext passwords over the wire. c. No encryption. d. Highest performance (native git protocol).

Anyone needing more is referred to webdav/ssh and assorted solutions. This minimises the dependencies on external libs, the only thing we need is a strong hash-function to implement (b); as it happens, we already have SHA1..

-- 
Sincerely,
           Stephen R. van den Berg.

"And now for something *completely* different!"
Previous: Shawn O. PearceNext: Shawn O. Pearce
Message 9 of 18 in “[RFC] Adding a challenge-response authentication method to git://”
  1. Stephen R. van den BergAug 13, 2008
  2. Petr BaudisAug 13, 2008
  3. David BrownAug 14, 2008
  4. Petr BaudisAug 14, 2008
  5. Stephen R. van den BergAug 14, 2008
  6. Petr BaudisAug 14, 2008
  7. Stephen R. van den BergAug 14, 2008
  8. Shawn O. PearceAug 13, 2008
  9. Stephen R. van den BergAug 13, 2008
  10. Shawn O. PearceAug 13, 2008
  11. Stephen R. van den BergAug 14, 2008
  12. Shawn O. PearceAug 14, 2008
  13. Stephen R. van den BergAug 14, 2008
  14. Andreas EricssonAug 14, 2008
  15. Stephen R. van den BergAug 14, 2008
  16. david@lang.hmAug 14, 2008
  17. david@lang.hmAug 14, 2008
  18. Shawn O. PearceAug 14, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.