git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: is gitosis secure?

From
RDRogan Dawes <lists@dawes.za.net>
Date
Dec 15, 2008, 07:52 UTC
Message-ID
<49460CD1.70305@dawes.za.net>
In-Reply-To
<alpine.DEB.1.10.0812150026570.17688@asgard.lang.hm>
david@lang.hm wrote:
Show 28 quoted lines
> On Mon, 15 Dec 2008, Rogan Dawes wrote:
> 
>> david@lang.hm wrote:
>>
>>>
>>> what would I like to see in an ideal world?
>>>
>>> something that runs as the git user, does not enable tunneling, and only
>>> does the data transfer functions needed for a push. it should use
>>> off-the-shelf libraries for certificate authentication and tie into PAM
>>> for additional authentication.
>>
>> How about a git-specific deployment/configuration of ssh? You can
>> certainly run multiple copies of SSH (on different ports), by providing
>> a restricted configuration file you can disable tunneling and any other
>> functionality that you don't like.
>>
>> And if you want it to run as a non-root user, simply choose a port>1024,
>> but keep in mind that you won't be able to authenticate by password
>> (IIRC, only key auth will work when running non-root), or setuid to
>> those users when they log in. Nonetheless, this could be sufficient for
>> gitosis, since everything runs as the specified user anyway, and IIRC,
>> gitosis wants individual SSH pubkeys to allow access.
> 
> IMHO this is better then exposing a 'normal' ssh daemon to the Internet
> just to be able to do a git push. the fact that you loose authentication
> options is not a good thing, are you sure that you cannot hook into PAM
> authentication for this?

I *think* that an unprivileged user cannot invoke PAM for accounts other than its own, and most certainly cannot change to that other user without being setuid (or having the appropriate capability).

Show 13 quoted lines
>> In many cases, especially if the tool is unix based, you can specify (in
>> ~/.ssh/config) a Proxy command that is executed before the SSH protocol
>> negotiation begins, which results in stdin and stdout being connected to
>> the SSH daemon at the destination. The most common variations are the
>> HTTP and Socks proxy connectors (e.g. corkscrew?), but the sky is really
>> the limit in terms of what is possible.
> 
> as I just commented, this looks like it's a per-user config option that
> is designed to be used as a proxy out of the network you are in to get
> to the Internet, not to be used at the far side of a connection to get
> to things on a remote network. as I understand it, you would need to
> change this config file for each different destination network you need
> to connect to.

That may be its original intention, but it can nonetheless be used for other purposes. Yes, you might need a different configuration for each network that you need to access, and quite possibly for each location that you need to access them from. This may result in config entry proliferation, but it is manageable, especially with the openssh wildcard syntax in the config file.

man ssh_config:

Host Restricts the following declarations (up to the next Host keyword) to be only for those hosts that match one of the patterns given after the keyword. If more than one pattern is provided, they should be separated by whitespace. A single `*' as a pattern can be used to provide global defaults for all hosts. The host is the hostname argument given on the command line (i.e. the name is not converted to a canonicalized host name before matching).

e.g
Host *-home
   ProxyCommand . . . .
FWIW.
Rogan
Previous: david@lang.hmNext: Jakub Narebski
Message 35 of 41 in “is gitosis secure?”
  1. Thomas KochDec 9, 2008
  2. Sam VilainDec 9, 2008
  3. Florian WeimerJan 18, 2009
  4. Boyd Stephen Smith Jr.Jan 18, 2009
  5. Florian WeimerJan 18, 2009
  6. Boyd Stephen Smith Jr.Jan 18, 2009
  7. Tommi VirtanenFeb 3, 2009
  8. Stephen R. van den BergFeb 4, 2009
  9. Tommi VirtanenFeb 4, 2009
  10. Stephen R. van den BergFeb 5, 2009
  11. Tommi VirtanenFeb 5, 2009
  12. R. Tyler BallanceDec 9, 2008
  13. Tommi VirtanenFeb 3, 2009
  14. Sverre RabbelierDec 9, 2008
  15. NixDec 13, 2008
  16. Sverre RabbelierDec 13, 2008
  17. Sitaram ChamartyDec 14, 2008
  18. david@lang.hmDec 14, 2008
  19. martinDec 14, 2008
  20. david@lang.hmDec 14, 2008
  21. Jakub NarebskiDec 14, 2008
  22. david@lang.hmDec 15, 2008
  23. martinDec 14, 2008
  24. david@lang.hmDec 15, 2008
  25. Mike HommeyDec 15, 2008
  26. david@lang.hmDec 15, 2008
  27. Mike HommeyDec 15, 2008
  28. TaitDec 15, 2008
  29. Sitaram ChamartyDec 14, 2008
  30. david@lang.hmDec 15, 2008
  31. Jakub NarebskiDec 14, 2008
  32. david@lang.hmDec 15, 2008
  33. Rogan DawesDec 15, 2008
  34. david@lang.hmDec 15, 2008
  35. Rogan DawesDec 15, 2008
  36. Jakub NarebskiDec 14, 2008
  37. NixDec 15, 2008
  38. david@lang.hmDec 15, 2008
  39. Asheesh LaroiaDec 15, 2008
  40. david@lang.hmDec 15, 2008
  41. Garry DolleyDec 9, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.