[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
56/66: programming-2022: Mention SSH signatures.
From: |
Ludovic Courtès |
Subject: |
56/66: programming-2022: Mention SSH signatures. |
Date: |
Wed, 29 Jun 2022 11:32:04 -0400 (EDT) |
civodul pushed a commit to branch master
in repository maintenance.
commit 56d74d1921e87fff0c9a506222564bc513a2ab7b
Author: Ludovic Courtès <ludo@gnu.org>
AuthorDate: Thu Apr 28 15:40:36 2022 +0200
programming-2022: Mention SSH signatures.
* doc/programming-2022/supply-chain.skb: Update footnote to mention
SSH signatures. Refer to git2021:relnotes instead of
huseby2021:git-crypto.
---
doc/programming-2022/security.sbib | 7 +++++++
doc/programming-2022/supply-chain.skb | 8 +++++---
2 files changed, 12 insertions(+), 3 deletions(-)
diff --git a/doc/programming-2022/security.sbib
b/doc/programming-2022/security.sbib
index cad19b5..0879f48 100644
--- a/doc/programming-2022/security.sbib
+++ b/doc/programming-2022/security.sbib
@@ -291,6 +291,13 @@ Thayer")
(year "2021")
(url "https://github.com/cryptidtech/git-cryptography-protocol"))
+(misc git2021:relnotes
+ (author "Git contributors")
+ (title "Git 2.34 Release Notes")
+ (year "2021")
+ (month "November")
+ (url
"https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.34.0.txt"))
+
(misc courtes2016:authentication
(author "Ludovic Courtès, Guix contributors")
(year "2016")
diff --git a/doc/programming-2022/supply-chain.skb
b/doc/programming-2022/supply-chain.skb
index 91b5486..cfd5cab 100644
--- a/doc/programming-2022/supply-chain.skb
+++ b/doc/programming-2022/supply-chain.skb
@@ -993,9 +993,11 @@ broad and extensible specification ,(ref :bib
More focused options such as minisign ,(ref :bib
'denis2021:minisign-web) looked more appealing. However, we felt that
the fact that OpenPGP commit signing is well-supported by Git,(footnote
-[As of this writing, Git tools only support OpenPGP, but work started in
-2021 to support cryptography tools other than OpenPGP/GnuPG ,(ref :bib
-'huseby2021:git-crypto).]) makes a significant practical difference:
+[When we started this work, the command-line Git tool would only support
+OpenPGP signatures. Since the release of Git 2.34.0 in November
+2021, one can additionally sign commits and tags with OpenSSH, the
+secure shell client ,(ref :bib 'git2021:relnotes).])
+makes a significant practical difference:
developers can easily be set up to sign commits with GnuPG and commands
such as ,(tt [git log]) can verify and display signatures; ways to deal
with OpenPGP keys and signatures, although complex, are also
- 28/66: icse-2022: Repurpose for <Programming> 2022., (continued)
- 28/66: icse-2022: Repurpose for <Programming> 2022., Ludovic Courtès, 2022/06/29
- 37/66: programming-2022: Improve rendering of in-line 'prog'., Ludovic Courtès, 2022/06/29
- 39/66: programming-2022: Add illustrations., Ludovic Courtès, 2022/06/29
- 40/66: programming-2022: Tweak., Ludovic Courtès, 2022/06/29
- 41/66: doc: Add CiSE article., Ludovic Courtès, 2022/06/29
- 34/66: programming-2022: Clarify bits., Ludovic Courtès, 2022/06/29
- 46/66: programming-2022: Fix typos and wording issues reported by reviewers., Ludovic Courtès, 2022/06/29
- 50/66: programming-2022: Address comments from Reviewer A., Ludovic Courtès, 2022/06/29
- 54/66: programming-2022: Use BibTeX for bibliography; include DOI., Ludovic Courtès, 2022/06/29
- 55/66: programming-2022: Clean up bibliography entries., Ludovic Courtès, 2022/06/29
- 56/66: programming-2022: Mention SSH signatures.,
Ludovic Courtès <=
- 57/66: programming-2022: Add channels and manifest., Ludovic Courtès, 2022/06/29
- 59/66: programming-2022: Cite actual full-source bootstrap., Ludovic Courtès, 2022/06/29
- 60/66: programming-2022: Add acknowledgments., Ludovic Courtès, 2022/06/29
- 61/66: programming-2022: Add \paperdetails for publication., Ludovic Courtès, 2022/06/29
- 64/66: programming-2022: Reference the artifact as requested., Ludovic Courtès, 2022/06/29
- 66/66: Merge branch 'wip-programming-paper', Ludovic Courtès, 2022/06/29