Re: git:// protocol over SSL/TLS
- From
- Konstantin Khomoutov <flatworm@users.sourceforge.net>
- Date
- Dec 27, 2013, 14:16 UTC
- Message-ID
- <20131227181640.314629cc762cab446ae5352e@domain007.com>
- In-Reply-To
- <87mwjm4c3s.fsf@igel.home>
On Fri, 27 Dec 2013 15:12:07 +0100 Andreas Schwab <schwab@linux-m68k.org> wrote:
Show 6 quoted lines
> > So guess we just need to recommend using https:// protocol instead > > of git:// for our users? > > Given how easy it is to verify the integrity of a git repository out > of band there isn't really much of added security by using TLS for > transport.
If the devs employ signed tags then yes but otherwise you'd have to have some reference repository to compare with. Sure they target for a more no-brainer setup. ;-)