git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Git push over git protocol for corporate environment

From
Matthieu Moy <matthieu.moy@grenoble-inp.fr>
Date
Oct 4, 2009, 16:26 UTC
Message-ID
<vpqtyyf5dn0.fsf@bauges.imag.fr>
In-Reply-To
<200910041725.39992.jnareb@gmail.com>
Jakub Narebski <jnareb@gmail.com> writes:
Show 13 quoted lines
> On Thu, 1 Oct 2009, Eugene Sajine wrote:
>
>> Thanks to everybody for prompt answers!
>
> You are welcome!
>
>> There is one thing I'm still missing though. Do I understand correctly that  
>> if a person has an ssh access (account) to the host in internal network,  
>> then this won't be enough for him to be able to push to the repo? Should we  
>> still go through the hassle of managing the ssh keys for each particular  
>> user who is supposed to have push access?
>
> Yes, it is enough to push (and fetch) via SSH protocol.

To be a bit more precise: roughly, there are two ways to manage access to a Git repo via SSH:

* One unix user (typically called "git") managing the repository, and
  eveybody connecting to the repo via ssh://git@.... Then, if you want
  any access control within the owned repositories for this user, you
  need a key-based authentication to be able to distinguish who's
  connecting. This is what gitorious does.
* Everyone has its own unix account, and the repository is shared (via
  ACLs or simple group-based permissions, see git init --shared).
  Then, each user can choose the way he prefers for authentication,
  and if the user has an unrestricted account (i.e. can write
  ~/.ssh/authorized_keys), then it's the job of the users to manage
  this, not the one of the sysadmin.
-- 
Matthieu Moy
http://www-verimag.imag.fr/~moy/
Previous: Jakub Narebski
Message 13 of 13 in “Git push over git protocol for corporate environment”
  1. Eugene SajineSep 30, 2009
  2. David BrownSep 30, 2009
  3. Jakub NarebskiSep 30, 2009
  4. Michael PooleSep 30, 2009
  5. Shawn O. PearceOct 1, 2009
  6. Marius Storm-OlsenOct 1, 2009
  7. Shawn O. PearceOct 1, 2009
  8. Eugene SajineOct 2, 2009
  9. Shawn O. PearceOct 2, 2009
  10. Eugene SajineOct 2, 2009
  11. Ismael LucenoOct 2, 2009
  12. Jakub NarebskiOct 4, 2009
  13. Matthieu MoyOct 4, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.