threads / discuss / 22416

git-tag -s can't find GPG private key

Subject: git-tag -s can't find GPG private key

## tl;dr

3 messages between Jan 27, 2010 and Jan 27, 2010.

replies: 2people: 3as markdown or json

Mike.lifeguard· Jan 27, 2010, 21:02 UTC · lore
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello,

It seems that when the GPG key name and user.name in git's config are different, git can't find the appropriate private key to sign the tag. Git should attempt to use user.email to find the key. Setting user.signingkey is of course a workaround. The relevant code would be in builtin-tag.c.

- -Mike
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAktgqewACgkQst0AR/DaKHuDZgCgpYHD05aJHKF/Wj/uU8CK5swP SccAoMjHVKM/OZBhbvSvC+aWCQ123Tje =ZIo0 -----END PGP SIGNATURE-----

Sverre Rabbelier· Jan 27, 2010, 21:06 UTC · re: Mike.lifeguard · lore

Re: git-tag -s can't find GPG private key

Heya,
On Wed, Jan 27, 2010 at 22:02, Mike.lifeguard <mike.lifeguard@gmail.com> wrote:
Show 5 quoted lines
> It seems that when the GPG key name and user.name in git's config are
> different, git can't find the appropriate private key to sign the tag.
> Git should attempt to use user.email to find the key. Setting
> user.signingkey is of course a workaround. The relevant code would be in
> builtin-tag.c.

It seems you already know where to look, why don't you try and come up with a patch since it is indeed, your itch to scratch?

-- 
Cheers,

Sverre Rabbelier
Junio C Hamano· Jan 27, 2010, 21:16 UTC · re: Mike.lifeguard · lore

Re: git-tag -s can't find GPG private key

"Mike.lifeguard" <mike.lifeguard@gmail.com> writes:
> It seems that when the GPG key name and user.name in git's config are
> different, git can't find the appropriate private key to sign the tag.
> Git should attempt to use user.email to find the key. Setting
> user.signingkey is of course a workaround.

user.signingkey was devised for this exact case, and I don't think it is a work-around.

I do not think "should attempt" is a correct attitude, even though I can 100% agree with "it would have been nicer if it attempted to do this from day one". You are unfortunately not interacting with git codebase in early 2005 anymore and there are thousands if not millions of existing users you should worry about.

Using user.email changes the behaviour for people who do not want a key that has the same e-mail address, and because the choice of key is all about security, the logic to choose which one shouldn't be changed lightly.

← back to recent threads