git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC PATCH 0/4] Teach git fetch to verify signed tags automatically

From
Johannes Schindelin <johannes.schindelin@gmx.de>
Date
Nov 28, 2008, 01:18 UTC
Message-ID
<alpine.DEB.1.00.0811280213140.30769@pacific.mpi-cbg.de>
In-Reply-To
<20081128000606.GB2759@euler>
Hi,
On Thu, 27 Nov 2008, Deskin Miller wrote:
Show 5 quoted lines
> This patch series mitigates this risk by trying to verify each signed 
> tag when it is first fetched.  Since, however, not everyone is concerned 
> with the security of signed tags, this feature tries to be conservative 
> insofar as signatures with public keys which are missing from the user's 
> keyring do not cause anything to be said about the tag's validity;

Now, in the context of security, this is not conservative. Conservative would be to fail as soon as a signature could not be verified, be it that there is no key to match against, or that the signature is corrupt.

Your notion to fail silently if the necessary keys were not found makes your patch series rather useless, no?

After all, the whole idea is to let Git check if every signature is correct, and when Git does not fail, rely on them being valid.

So I think that the _only_ thing that would make sense is to fail _unless_ all the signatures were verified to be correct.

_That_ is why I want this feature to be off by default.

Ciao, Dscho

Previous: Deskin MillerNext: Johannes Schindelin
Message 13 of 16 in “Teach git fetch to verify signed tags automatically”
  1. 0/4 Teach git fetch to verify signed tags automaticallyDeskin Miller, Nov 24, 2008
  2. 1/4 Refactor builtin-verify-tag.cDeskin Miller, Nov 24, 2008
  3. 2/4 verify-tag.c: ignore SIGPIPE around gpg invocationDeskin Miller, Nov 24, 2008
  4. 3/4 verify-tag.c: suppress gpg output if askedDeskin Miller, Nov 24, 2008
  5. 4/4 Make git fetch verify signed tagsDeskin Miller, Nov 24, 2008
  6. Johannes SchindelinNov 24, 2008
  7. Deskin MillerNov 28, 2008
  8. Johannes SchindelinNov 24, 2008
  9. Deskin MillerNov 28, 2008
  10. Junio C HamanoNov 24, 2008
  11. Junio C HamanoNov 24, 2008
  12. Deskin MillerNov 28, 2008
  13. Johannes SchindelinNov 28, 2008
  14. Johannes SchindelinNov 24, 2008
  15. Deskin MillerNov 28, 2008
  16. Junio C HamanoNov 28, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.