git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH] gpg: add support for gpgsm

From
Jeff King <peff@peff.net>
Date
Mar 31, 2016, 15:57 UTC
Message-ID
<20160331155753.GA1006@sigill.intra.peff.net>
In-Reply-To
<xmqqa8ler6pu.fsf@gitster.mtv.corp.google.com>
On Thu, Mar 31, 2016 at 08:46:05AM -0700, Junio C Hamano wrote:
Show 21 quoted lines
> Carlos Martín Nieto <cmn@dwim.me> writes:
> 
> > Detect the gpgsm block header and run this command instead of gpg.
> > On the signing side, ask gpgsm if it knows the signing key we're trying
> > to use and fall back to gpg if it does not.
> >
> > This lets the user more easily combine signing and verifying X509 and
> > PGP signatures without having to choose a default for a particular
> > repository that may need to be occasionally overridden.
> >
> > Signed-off-by: Carlos Martín Nieto <cmn@dwim.me>
> >
> > ---
> >
> > Out there in the so-called "real world", companies like using X509 to
> > sign things. Currently you can set 'gpg.program' to gpgsm to get
> > gpg-compatible verification,...
> 
> I notice that you had to add GPGSM_MESSAGE string constant; does the
> current code without any change really work correctly if you set
> 'gpg.program' to gpgsm and do nothing else?

It has been a few months since I fooled around with gpgsm, but IIRC, it works for tags but not commits. Because verify-tag just blindly dumps the tag to gpg.program, and gpgsm finds the correct signature. Whereas the --show-signature option of git-log does not bother to call gpg if we didn't see a signature.

Which makes me wonder whether verify-tag would send a gpgsm-signed tag to the right place with Carlos's patch (I didn't check).

-Peff
Previous: Junio C HamanoNext: Carlos Martín Nieto
Message 6 of 8 in “gpg: add support for gpgsm”
  1. gpg: add support for gpgsmCarlos Martín Nieto, Mar 31, 2016
  2. Jeff KingMar 31, 2016
  3. Carlos Martín NietoMar 31, 2016
  4. Junio C HamanoMar 31, 2016
  5. Junio C HamanoMar 31, 2016
  6. Jeff KingMar 31, 2016
  7. Carlos Martín NietoMar 31, 2016
  8. Jeff KingMar 31, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.