git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC] Adding a challenge-response authentication method to git://

From
Petr Baudis <pasky@suse.cz>
Date
Aug 14, 2008, 11:39 UTC
Message-ID
<20080814113901.GR10151@machine.or.cz>
In-Reply-To
<20080814110739.GI9680@cuci.nl>
On Thu, Aug 14, 2008 at 01:07:39PM +0200, Stephen R. van den Berg wrote:
Show 7 quoted lines
> Well, I looked into gitosis, and it solves part of the problem, it has a
> few downsides though:
> 
> - It depends on Python for no particular reason (it might as well have
>   been built using shellscripts only, or if need be Perl, since git
>   already uses that); yet any extra dependency is creating an extra
>   hurdle for portability and adoption.

Is this concern really any kind of practical one? To me it appears that Python and Perl are both so extremely wide-spread that this might be issue only on embedded systems, exotic systems with very low proportion of git users, and users with strong ideological opinions about the system (probably low proportion of git users too).

Show 8 quoted lines
> - It does authentication magic without properly documenting why it does
>   it properly.
> - It explicitly warns that it needs PATH and PYTHON_PATH magic and that
>   using it without setting those up has not been tested; this does not
>   inspire confidence that the security of the solution is airtight.
> 
> Other than that, gitosis looks fairly good if you want to use public
> keys.

This doesn't seem to be convincing reason for _reimplementing_ the solution. (Of course, I don't prevent you from doing that, I'm just wondering about the feasibility.)

-- 
				Petr "Pasky" Baudis
The next generation of interesting software will be done
on the Macintosh, not the IBM PC.  -- Bill Gates
Previous: Stephen R. van den BergNext: Stephen R. van den Berg
Message 6 of 18 in “[RFC] Adding a challenge-response authentication method to git://”
  1. Stephen R. van den BergAug 13, 2008
  2. Petr BaudisAug 13, 2008
  3. David BrownAug 14, 2008
  4. Petr BaudisAug 14, 2008
  5. Stephen R. van den BergAug 14, 2008
  6. Petr BaudisAug 14, 2008
  7. Stephen R. van den BergAug 14, 2008
  8. Shawn O. PearceAug 13, 2008
  9. Stephen R. van den BergAug 13, 2008
  10. Shawn O. PearceAug 13, 2008
  11. Stephen R. van den BergAug 14, 2008
  12. Shawn O. PearceAug 14, 2008
  13. Stephen R. van den BergAug 14, 2008
  14. Andreas EricssonAug 14, 2008
  15. Stephen R. van den BergAug 14, 2008
  16. david@lang.hmAug 14, 2008
  17. david@lang.hmAug 14, 2008
  18. Shawn O. PearceAug 14, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.