Re: [RFC] Adding a challenge-response authentication method to git://

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, Aug 14, 2008 at 01:07:39PM +0200, Stephen R. van den Berg wrote:
> Well, I looked into gitosis, and it solves part of the problem, it has a
> few downsides though:
> 
> - It depends on Python for no particular reason (it might as well have
>   been built using shellscripts only, or if need be Perl, since git
>   already uses that); yet any extra dependency is creating an extra
>   hurdle for portability and adoption.

Is this concern really any kind of practical one? To me it appears that
Python and Perl are both so extremely wide-spread that this might be
issue only on embedded systems, exotic systems with very low proportion
of git users, and users with strong ideological opinions about the
system (probably low proportion of git users too).

> - It does authentication magic without properly documenting why it does
>   it properly.
> - It explicitly warns that it needs PATH and PYTHON_PATH magic and that
>   using it without setting those up has not been tested; this does not
>   inspire confidence that the security of the solution is airtight.
> 
> Other than that, gitosis looks fairly good if you want to use public
> keys.

This doesn't seem to be convincing reason for _reimplementing_ the
solution. (Of course, I don't prevent you from doing that, I'm just
wondering about the feasibility.)

-- 
				Petr "Pasky" Baudis
The next generation of interesting software will be done
on the Macintosh, not the IBM PC.  -- Bill Gates
--
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Kernel Development]     [Gcc Help]     [IETF Annouce]     [DCCP]     [Netdev]     [Networking]     [Security]     [V4L]     [Bugtraq]     [Yosemite]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux SCSI]     [Fedora Users]

  Powered by Linux