Thread (21 messages) flat view 21 messages, 5 authors, 2016-06-15

Re: [RFC] Authenticate push via PGP signature, not SSH

From: Shawn O. Pearce <hidden>
Date: 2016-06-15 22:44:08

Sam Vilain [off-list ref] wrote:
Shawn O. Pearce wrote:
quoted
But in a smaller business type setting, where there's under 100
employees working, odds are you've already created the user account
on systems, and physically passed the initial password via a sticky
note after checking the person's government issued IDs.  In such a
setting having yet another authentication system (PGP keys) is just
yet more work for the already over worked/under appreciated IT staff.
Agreed - again I'd personally consider allowing receive-pack with
reflogs in those environments if setting up PGP or SSH keys was a hassle.
Yea, I already have reflogs enabled for all stored branches on the
central server.  And since some branches have a no-delete policy
(based upon the rules offered by contrib/hooks/update-paranoid) the
reflogs are also effectively no-delete, even if the branch rewinds.

I also never run `git reflog expire`.  I might in another year or
so consider it, but most of my no-delete branches also don't rewind
very often (if ever) so there's very little disk to be gained by
reflog expiry.

-- 
Shawn.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help