git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2] signature-format.txt: note SSH and X.509 signature delimiters

From
Gwyneth Morgan <gwymor@tilde.club>
Date
Feb 27, 2023, 20:26 UTC
Message-ID
<Y/0R3lDyJrtd4gIZ@tilde.club>
In-Reply-To
<230210.86ilg9wzho.gmgdl@evledraar.gmail.com>
On 2023-02-10 11:52:42+0100, Ævar Arnfjörð Bjarmason wrote:
Show 13 quoted lines
> 
> On Fri, Feb 10 2023, Gwyneth Morgan wrote:
> 
> > This document only explained PGP signatures, but Git now supports X.509
> > and SSH signatures.
> 
> To elaborate a bit, in 1e7adb97566 (gpg-interface: introduce new
> signature format "x509" using gpgsm, 2018-07-17) we added X.509, and in
> 29b315778e9 (ssh signing: add ssh key format and signing code,
> 2021-09-10) we added "ssh", but our docs were never updated.
> 
> Your commit message says as much in briefer terms, but maybe if you
> re-roll having those references would help put this change in context.>
I'll reference those commits in v3.
Show 7 quoted lines
> > +Signatures begin with an ASCII Armor header line and end with a tail line,
> > +which differ depending on signature type.
> 
> Does the "ASCII Armor header" really add something here, or just confuse
> the user with a reference that's not followed-up or explained here?
> Maybe we should point out OpenPGP's '--armor' option in passing, to note
> to the reader that this isn't some git-specific concept.

I think having a relevant term to search for online and in manpages is helpful. Mentioning the specific command-line option seems unnecessary, but I'll put the term "ASCII Armor" in quotes to make it clearer that this is not a git-specific concept.

Show 17 quoted lines
> I wonder if structuring it like this wouldn't help make this easier to
> read, and reduce the repetition, as well as making the circular
> references between this & 'gpg.format' more obvious:
> 
> 	The signature start and end marker comes on its own line, and
> 	differs based on the signature type (as selected by
> 	'gpg.format', see linkgit:git-config[1]).
> 
>         Those are, for values of 'gpg.format':
> 
>         gpg: `-----BEGIN PGP SIGNATURE-----` and `-----END PGP
>              SIGNATURE-----`. Or, if GPG has been asked to produce
>              RFC1991 signatures: `-----BEGIN PGP MESSAGE-----` and
>              `-----END PGP MESSAGE-----`
> 
>         x509: `-----BEGIN SIGNED MESSAGE-----` `-----END SIGNED MESSAGE-----`
> 	ssh:`-----BEGIN SSH SIGNATURE-----` and `-----END SSH SIGNATURE-----`

Looks good. I'll do this in v3. I'll reference these by the gpg.format value, as well as a parenthetical proper name, like "gpg (PGP)"; these are basically the same the other two formats, but I want it to be clear that `gpg` signatures don't have to be from the gpg program but could be from any PGP-supporting program.

> Then for gpg.format in Documentation/config/gpg.txt we could add e.g.:
> 
> 	See linkgit:gitformat-signature[5] for the signature format,
> 	which differs based on the selected 'gpg.format'.
OK.
Thanks.
Previous: Ævar Arnfjörð BjarmasonNext: Junio C Hamano
Message 8 of 11 in “signature-format.txt: Note SSH and X.509 signature delimiters”
  1. signature-format.txt: Note SSH and X.509 signature delimitersGwyneth Morgan, Jan 20, 2022
  2. Junio C HamanoJan 20, 2022
  3. Junio C HamanoJan 20, 2022
  4. Gwyneth MorganFeb 10, 2023
  5. Junio C HamanoFeb 10, 2023
  6. signature-format.txt: note SSH and X.509 signature delimitersGwyneth Morgan, Feb 10, 2023
  7. Ævar Arnfjörð BjarmasonFeb 10, 2023
  8. Gwyneth MorganFeb 27, 2023
  9. Junio C HamanoFeb 10, 2023
  10. signature-format.txt: note SSH and X.509 signature delimitersGwyneth Morgan, Feb 27, 2023
  11. Junio C HamanoFeb 27, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.