git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: User authentication in GIT

From
Jakub Narebski <jnareb@gmail.com>
Date
Feb 7, 2012, 09:12 UTC
Message-ID
<m3aa4vknwv.fsf@localhost.localdomain>
In-Reply-To
<1328595129258-7261349.post@n2.nabble.com>
supadhyay <supadhyay@imany.com> writes:
> I want to migrate my existing version control system (CVS) into GIT. The
> first question which comes to me is in CVS we have user authentication like
> username and their password while in GIT there is SSH authentication. 
Do you use _unencrypted_ pserver, or tunelling over SSH (with CVS_RSH)?
 
> Can any one suggest me what is the optimal way to manage the users in GIT?
> Does all users having username, passoword and SSH key? or there is no users
> credential but only SSH authentication? if I have 1000 users in old system
> CVS then do I need to create a key for all 1000 users in GIT? or etc.

First, Git supports unauthenticated anonymous fetching via custom git:// protocol and via HTTP. If you only need read-only access to repository, it would be enough. No account or SSH key necessary.

Second, Git uses SSH for authenthication instead of hand-rolling its own security system, badly. You don't need to create 1000 shell accounts for SSH access: use tool like gitolite to manage git repositories, which uses public-key infrastructure without need to generate 1000 accounts. You would still need for each user to generate their own SSH key.

See gitolite documentation for more detail (older gitosis tool is no longer maintained, as far as I know).

HTH
-- 
Jakub Narebski
Previous: Robin H. JohnsonNext: supadhyay
Message 3 of 13 in “User authentication in GIT”
  1. supadhyayFeb 7, 2012
  2. Robin H. JohnsonFeb 7, 2012
  3. Jakub NarebskiFeb 7, 2012
  4. supadhyayFeb 7, 2012
  5. compufreakFeb 7, 2012
  6. Johan HerlandFeb 7, 2012
  7. supadhyayFeb 7, 2012
  8. Sitaram ChamartyFeb 7, 2012
  9. supadhyayFeb 10, 2012
  10. Sitaram ChamartyFeb 11, 2012
  11. supadhyayFeb 13, 2012
  12. Sitaram ChamartyFeb 13, 2012
  13. supadhyayFeb 13, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.