Thread (14 messages) 14 messages, 4 authors, 2016-06-15

Re: [PATCH] tag,verify-tag: do not trip over rfc1991 signatures

From: Michael J Gruber <hidden>
Date: 2016-06-15 22:49:42

Todd Zullinger venit, vidit, dixit 05.10.2010 22:42:
Michael J Gruber wrote:
quoted
Currently, git expects "-----BEGIN PGP SIGNATURE-----" at the beginning of a
signature. But gpg uses "MESSAGE" instead of "SIGNATURE" when used with
the "rfc1991" option. This leads to git's faling to verify it's own
signed tags.

Be more lenient and take "-----BEGIN PGP " as the indicator.
Another way to go might be to add --gnupg (or --openpgp) to the gpg
options used for tagging.  That overrides an option like rfc1991 in
the gnupg config file.

Whether that's preferable to accepting these older-style messages is
debatable.  Using rfc1991 implies pgp-2.x compatibility, which means
using md5 as the algorithm.  It could be seen as a weakness to accept
such signatures.
The problem is that we never did this, i.e. we always allowed people to
create such signatures. They never verified, though, even though they
were valid. If that's reason enough to discount the usual compatibility
argument then adding --gnupg would be best.
(Oh, and you probably saw this already, but s/faling/failing. ;)
:|

Michael
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help