# Preventing unsigned commit/merge/tag

2 messages from 2013-12-31 to 2013-12-31. Participants: shawn wilson, brian m. carlson.
Thread: https://gitlist.dev/t/35593

## shawn wilson, 2013-12-31 17:49

Subject: Preventing unsigned commit/merge/tag
Message-ID: <CAH_OBicyrd=H1uG+_5-Jz=gK0fLsPbKKhkypWDG5yNb0umnhiw@mail.gmail.com>
URL: https://gitlist.dev/e/CAH_OBicyrd%3DH1uG%2B_5-Jz%3DgK0fLsPbKKhkypWDG5yNb0umnhiw%40mail.gmail.com

```
What's the best way of doing this? I'd prefer this be a pre hook on
the server that rejects and the user has to rebase and fix their
stuff. Though, if there's some way to make it easier for users not to
mess up (other than an alias for everything which I'll probably do
anyway) that would be useful. Any ideas?

```

## brian m. carlson, 2013-12-31 19:27

Subject: Re: Preventing unsigned commit/merge/tag
Message-ID: <20131231192736.GI451338@vauxhall.crustytoothpaste.net>
URL: https://gitlist.dev/e/20131231192736.GI451338%40vauxhall.crustytoothpaste.net
In-Reply-To: <CAH_OBicyrd=H1uG+_5-Jz=gK0fLsPbKKhkypWDG5yNb0umnhiw@mail.gmail.com>

```
On Tue, Dec 31, 2013 at 12:49:01PM -0500, shawn wilson wrote:
> What's the best way of doing this? I'd prefer this be a pre hook on
> the server that rejects and the user has to rebase and fix their
> stuff. Though, if there's some way to make it easier for users not to
> mess up (other than an alias for everything which I'll probably do
> anyway) that would be useful. Any ideas?

I don't believe the sign-on-rebase stuff ever got picked up, so at the
moment this wouldn't be a good idea, since each and every commit would
have to be manually amended.  It seems it never made it from the list
into Junio's queue whatsoever.  And the always-sign code is only in pu
at the moment.

But if you wanted to anyway, you could simply use a pre-receive hook and
walk the tree, verifying the signatures of each commit against some
canonical list of approved keys.

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187

```
