git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: upstreaming https://github.com/cgwalters/git-evtag ?

From
Santiago Torres <santiago@nyu.edu>
Date
Jan 10, 2018, 16:38 UTC
Message-ID
<20180110163856.5uy4lbon322ey3ns@LykOS.localdomain>
In-Reply-To
<20180109203849.GA30468@aiede.svl.corp.google.com>
Show 15 quoted lines
> > push for hash-agnosticity. I don't know if git-evtag is hash agnostic,
> > but if it is not, then we have two transition plans to think about.
> 
> I don't think there's even a question here: Git has to transition off
> of SHA-1.
> 
> In that context, Stefan's comment is a welcome one: once we've
> transitioned off of SHA-1, having a separate evtag feature would make
> git more complicated without any benefit to match.  To put it another
> way, the gpgsig-sha256 field described in
> Documentation/technical/hash-function-transition.txt provides
> essentially the same functionality as an evtag.  What's missing is an
> implementation of it.
> 
> I'm happy to help in any way I can (reviews, advice, etc).
Same here, although I'm a bit swamped with other work... 
Show 8 quoted lines
> 
> > Full disclosure, I published a "competing" solution a couple of years
> > ago[1] but, in my personal opinion, I think push certificates can
> > achieve the same security guarantees as my system with very little
> > changes.
> 
> Work to improve the usability of push certs would also be very very
> welcome.

I agree. I personally think that at least the sample hook work on here would be a good candidate for this[1], although I don't know what's the status of it. The way they are right now, they should at least warn when push certificates are not enabled on the server side (i.e., there is no hook to handle it).

> 
> Thanks and hope that helps,
> Jonathan
No, thanks to you :)
-Santiago.
[1] https://public-inbox.org/git/20171202091248.6037-1-root@shikherverma.com/
Previous: Jonathan Nieder
Message 11 of 11 in “upstreaming https://github.com/cgwalters/git-evtag ?”
  1. Colin WaltersJan 8, 2018
  2. Johannes SchindelinJan 8, 2018
  3. Santiago TorresJan 8, 2018
  4. Colin WaltersJan 8, 2018
  5. Santiago TorresJan 8, 2018
  6. Stefan BellerJan 8, 2018
  7. Santiago TorresJan 8, 2018
  8. Colin WaltersJan 9, 2018
  9. Santiago TorresJan 9, 2018
  10. Jonathan NiederJan 9, 2018
  11. Santiago TorresJan 10, 2018

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.