From: Shawn Pearce <spearce@spearce.org>
To: Johannes Schindelin <Johannes.Schindelin@gmx.de>
Cc: git@vger.kernel.org
Subject: Re: Locked down (but still shared) repositories
Date: Thu, 7 Dec 2006 14:17:30 -0500 [thread overview]
Message-ID: <20061207191730.GA12143@spearce.org> (raw)
In-Reply-To: <Pine.LNX.4.63.0612071640160.28348@wbgn013.biozentrum.uni-wuerzburg.de>
Johannes Schindelin <Johannes.Schindelin@gmx.de> wrote:
> On Thu, 7 Dec 2006, Shawn Pearce wrote:
>
> > For various auditing reasons the repositories need to be tightly
> > controlled. That is the following cannot be permitted:
> >
> > [...]
>
> How about just one such user? After all, you already have this user: the
> repo owner. Of course, people have to push via ssh, even on the same
> machine.
How do I know which SSH key the client used to connect? Remember I'm
looking at the real uid to determine who is performing the operation.
In the situation you describe everyone looks the same to the
update hook...
For (probably stupid) reasons the server is the commerial F-Secure
SSH server, btw. So OpenSSH based things wouldn't apply. And best
that I can tell, F-Secure SSH won't tell me which key was used
to authenticate.
--
next prev parent reply other threads:[~2006-12-07 19:17 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-12-07 11:35 Locked down (but still shared) repositories Shawn Pearce
2006-12-07 12:21 ` Martin Waitz
2006-12-07 15:42 ` Johannes Schindelin
2006-12-07 19:17 ` Shawn Pearce [this message]
2006-12-07 19:45 ` Rogan Dawes
2006-12-07 20:16 ` Shawn Pearce
2006-12-07 20:16 ` Randal L. Schwartz
2006-12-07 20:32 ` Rogan Dawes
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20061207191730.GA12143@spearce.org \
--to=spearce@spearce.org \
--cc=Johannes.Schindelin@gmx.de \
--cc=git@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).