# Allow "-u" flag to tag signing

4 messages from 2005-10-06 to 2005-10-06. Participants: Linus Torvalds, H. Peter Anvin, Junio C Hamano, Chris Wright.
Thread: https://gitlist.dev/t/2032

## Linus Torvalds, 2005-10-06 16:58

Subject: Allow "-u" flag to tag signing
Message-ID: <Pine.LNX.4.64.0510060952410.31407@g5.osdl.org>
URL: https://gitlist.dev/e/Pine.LNX.4.64.0510060952410.31407%40g5.osdl.org

```

The current "git tag -s" thing always uses the tagger name as the signing 
user key, which is very irritating, since my key is under my email 
address, but the tagger key obviously contains the actual machine name 
too.

Now, I could just use "GIT_COMMITTER_EMAIL" and force it to be my real 
email, but I actually think that it's nice to see which machine I use for 
my work. 

So rather than force my tagger ID to have to match the gpg key name, just 
support the "-u" flag to "git tag" instead. It implicitly enables signing, 
since it doesn't make any sense without it. Thus:

	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]

will use the named gpg key for signing.

Signed-off-by: Linus Torvalds <torvalds@osdl.org>
---
Not very well tested, but I re-did my v2.6.14-rc3 tag with this, since I'd 
messed up the comments (and called it v2.6.14-rc2 in there ;)

So it may even work.

diff --git a/git-tag.sh b/git-tag.sh
--- a/git-tag.sh
+++ b/git-tag.sh
@@ -12,6 +12,7 @@ annotate=
 signed=
 force=
 message=
+username=
 while case "$#" in 0) break ;; esac
 do
     case "$1" in
@@ -30,6 +31,12 @@ do
 	shift
 	message="$1"
 	;;
+    -u)
+	annotate=1
+	signed=1
+	shift
+	username="$1"
+	;;
     -*)
         usage
 	;;
@@ -70,8 +77,11 @@ if [ "$annotate" ]; then
     ( echo -e "object $object\ntype $type\ntag $name\ntagger $tagger\n"; cat .tagmsg ) > .tmp-tag
     rm -f .tmp-tag.asc .tagmsg
     if [ "$signed" ]; then
-	me=$(expr "$tagger" : '\(.*>\)') &&
-	gpg -bsa -u "$me" .tmp-tag &&
+	{
+		[ "$username" ] ||
+		username=$(expr "$tagger" : '\(.*>\)')
+	} &&
+	gpg -bsa -u "$username" .tmp-tag &&
 	cat .tmp-tag.asc >>.tmp-tag ||
 	die "failed to sign the tag with GPG."
     fi

```

## H. Peter Anvin, 2005-10-06 17:15

Subject: Re: Allow "-u" flag to tag signing
Message-ID: <43455BBC.6020908@zytor.com>
URL: https://gitlist.dev/e/43455BBC.6020908%40zytor.com
In-Reply-To: <Pine.LNX.4.64.0510060952410.31407@g5.osdl.org>

```
Linus Torvalds wrote:
> The current "git tag -s" thing always uses the tagger name as the signing 
> user key, which is very irritating, since my key is under my email 
> address, but the tagger key obviously contains the actual machine name 
> too.
> 
> Now, I could just use "GIT_COMMITTER_EMAIL" and force it to be my real 
> email, but I actually think that it's nice to see which machine I use for 
> my work. 
> 
> So rather than force my tagger ID to have to match the gpg key name, just 
> support the "-u" flag to "git tag" instead. It implicitly enables signing, 
> since it doesn't make any sense without it. Thus:
> 
> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
> 
> will use the named gpg key for signing.

This is important for another reason as well: a lot of people have 
multiple keys.

	-hpa

```

## Junio C Hamano, 2005-10-06 20:17

Subject: Re: Allow "-u" flag to tag signing
Message-ID: <7vwtkq8kne.fsf@assigned-by-dhcp.cox.net>
URL: https://gitlist.dev/e/7vwtkq8kne.fsf%40assigned-by-dhcp.cox.net
In-Reply-To: <43455BBC.6020908@zytor.com>

```
"H. Peter Anvin" <hpa@zytor.com> writes:

>> ... It implicitly enables signing, since it doesn't make any
>> sense without it. Thus:
>> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
>> will use the named gpg key for signing.
>
> This is important for another reason as well: a lot of people have 
> multiple keys.

Agreed.  Thanks both.  Will apply.

```

## Chris Wright, 2005-10-06 23:32

Subject: Re: Allow "-u" flag to tag signing
Message-ID: <20051006233200.GR8041@shell0.pdx.osdl.net>
URL: https://gitlist.dev/e/20051006233200.GR8041%40shell0.pdx.osdl.net
In-Reply-To: <Pine.LNX.4.64.0510060952410.31407@g5.osdl.org>

```
* Linus Torvalds (torvalds@osdl.org) wrote:
> So rather than force my tagger ID to have to match the gpg key name, just 
> support the "-u" flag to "git tag" instead. It implicitly enables signing, 
> since it doesn't make any sense without it. Thus:
> 
> 	git tag -u <gpg-key-name> <tag-name> [<tagged-object>]
> 
> will use the named gpg key for signing.

Nice, I've had a hack something like this locally here as well, and been
meaning to cleanup and submit.

thanks,
-chris

```
