git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git signed push server-side

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 26, 2017, 01:16 UTC
Message-ID
<xmqqo9r3qgak.fsf@gitster.mtv.corp.google.com>
In-Reply-To
<20170826003229.GL13924@aiede.mtv.corp.google.com>
Jonathan Nieder <jrnieder@gmail.com> writes:
> I think respecting gpg.program would be nicer.  Is there a reason not
> to do that?
>
> I suspect receive-pack just forgot to call git_gpg_config.
That would be a good change.
> How is the keyring configured for other commands that use GPG, like
> "git tag -v"?  (Forgive my laziness in not looking it up.)

AFAIR we never do anything special, so you should be able to point GNUPGHOME to wherever you like to use the desired configuration.

Show 5 quoted lines
> I also wonder why you say the git configuration system is unsuited to
> keeping secrets.  E.g. passing an include.path setting with -c or
> GIT_CONFIG_PARAMETERS should avoid the kinds of trouble you described.
> Is there a change we could make to make it work better?  That said, I
> think being able to name a file is a good idea.

I also wonder that too. The configuration file that has the filename could be made just as secret and unreadable from public as the new file that stores the seed with the same mechanism, I would imagine.

Show 5 quoted lines
>> 5. There are no docs on how to use this feature properly
>>    (Debian #852695, #852688 part 1)
>>
>> Using the signed push feature requires careful programming on the
>> server side.  There should be a doc explaining how to do this.

This was rather deliberately left underspecified, hoping that the BCP would emerge after people gain experience. As Ian is looking into this and hopefully gain real-world experience, we can have a good BCP description after he is done with his project ;-)

> Yes, that sounds like a very welcome kind of thing to add.
Indeed.
Previous: Junio C HamanoNext: Ian Jackson
Message 5 of 6 in “git signed push server-side”
  1. Ian JacksonAug 25, 2017
  2. Junio C HamanoAug 25, 2017
  3. Jonathan NiederAug 26, 2017
  4. Junio C HamanoAug 26, 2017
  5. Junio C HamanoAug 26, 2017
  6. Ian JacksonAug 26, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.