Commit graph

5292 commits

Author SHA1 Message Date
https://www.google.com/accounts/o8/id?id=AItOawn0hu_TPhLcUM1Ivvn7iIoZ_iD3g_5WDcs
e874022aa3 2014-10-03 20:58:10 +00:00
https://www.google.com/accounts/o8/id?id=AItOawn0hu_TPhLcUM1Ivvn7iIoZ_iD3g_5WDcs
01b923c2c5 2014-10-03 01:05:23 +00:00
http://joeyh.name/
1da90ba34c Added a comment 2014-10-02 16:09:37 +00:00
http://joeyh.name/
d069761098 Added a comment 2014-10-02 15:35:16 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlM_DRhi_5pJrTA0HbApHR25iAgy-NBXTY
e0cc2f2653 Added a comment 2014-10-01 22:39:01 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlM_DRhi_5pJrTA0HbApHR25iAgy-NBXTY
44918b9571 Added a comment 2014-10-01 22:25:24 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlM_DRhi_5pJrTA0HbApHR25iAgy-NBXTY
bc1d83daf1 removed 2014-10-01 22:08:31 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlM_DRhi_5pJrTA0HbApHR25iAgy-NBXTY
21da748706 Added a comment 2014-10-01 22:02:56 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlM_DRhi_5pJrTA0HbApHR25iAgy-NBXTY
f84de2760d Added a comment 2014-10-01 22:02:44 +00:00
stp
5a79b19a4d Added a comment: Any update 2014-10-01 12:48:06 +00:00
stp
e390e28316 removed 2014-10-01 12:47:18 +00:00
stp
b574984534 removed 2014-10-01 12:46:53 +00:00
stp
7edd109c4e Added a comment: Any update 2014-10-01 12:46:35 +00:00
stp
1ad4058ec3 Added a comment: Any update 2014-10-01 12:46:24 +00:00
stp
3ed2efac95 Added a comment: Any update 2014-10-01 12:46:13 +00:00
https://www.google.com/accounts/o8/id?id=AItOawmyYyXrtGKiR3Pu2OjdVsETXf4ePmECW54
0bfc4875e2 Added a comment 2014-09-29 10:48:37 +00:00
https://www.google.com/accounts/o8/id?id=AItOawl9sYlePmv1xK-VvjBdN-5doOa_Xw-jH4U
cbd772eaff Added a comment 2014-09-29 08:09:33 +00:00
https://www.google.com/accounts/o8/id?id=AItOawl9sYlePmv1xK-VvjBdN-5doOa_Xw-jH4U
e17316b01d Added a comment 2014-09-29 08:07:55 +00:00
https://www.google.com/accounts/o8/id?id=AItOawk0GR7KgDF6PAzHTkLZCCkjAvJVB7ceXTY
1d29045eb6 Added a comment 2014-09-27 19:46:08 +00:00
Joey Hess
f6ba9b55b7 close 2014-09-27 11:26:01 -04:00
https://www.google.com/accounts/o8/id?id=AItOawk0GR7KgDF6PAzHTkLZCCkjAvJVB7ceXTY
c83d5b7f44 2014-09-27 10:14:23 +00:00
https://www.google.com/accounts/o8/id?id=AItOawlg2AidDIIx7EfjLXhyyRtWyWLg_0yxilE
698cf54426 2014-09-27 00:23:56 +00:00
Joey Hess
5cfa5213d2 Merge branch 'master' of ssh://git-annex.branchable.com 2014-09-26 15:37:59 -04:00
JerSou
b827558f39 Added a comment 2014-09-25 19:27:43 +00:00
JerSou
3cc9b960d9 removed 2014-09-25 19:26:58 +00:00
JerSou
62e2c3e9c9 Added a comment 2014-09-25 19:26:03 +00:00
Joey Hess
459db7a367 Merge branch 'master' of ssh://git-annex.branchable.com 2014-09-24 10:52:03 -04:00
http://svario.it/gioele
f47cebf38e Added a comment 2014-09-24 07:15:09 +00:00
https://www.google.com/accounts/o8/id?id=AItOawmK0703vNSIQsP1mGf-4MAPnsBZiSc6yVo
7c8f63107d Added a comment 2014-09-23 21:15:29 +00:00
https://www.google.com/accounts/o8/id?id=AItOawmK0703vNSIQsP1mGf-4MAPnsBZiSc6yVo
a29dba3027 Added a comment 2014-09-23 20:58:10 +00:00
http://joeyh.name/
c31ea37104 Added a comment 2014-09-23 20:27:25 +00:00
Joey Hess
21672e7b17 close 2014-09-23 16:19:45 -04:00
dirkz
b0c4300868 2014-09-20 14:55:36 +00:00
https://www.google.com/accounts/o8/id?id=AItOawmK0703vNSIQsP1mGf-4MAPnsBZiSc6yVo
70813b0e29 2014-09-19 21:45:42 +00:00
http://joeyh.name/
9ad3746abb Added a comment 2014-09-19 18:33:17 +00:00
annexuser
80232ac871 Added a comment 2014-09-19 04:43:42 +00:00
Joey Hess
2f3c3aa01f glacier, S3: Fix bug that caused embedded creds to not be encypted using the remote's key.
encryptionSetup must be called before setRemoteCredPair. Otherwise,
the RemoteConfig doesn't have the cipher in it, and so no cipher is used to
encrypt the embedded creds.

This is a security fix for non-shared encryption methods!

For encryption=shared, there's no security problem, just an
inconsistentency in whether the embedded creds are encrypted.

This is very important to get right, so used some types to help ensure that
setRemoteCredPair is only run after encryptionSetup. Note that the external
special remote bypasses the type safety, since creds can be set after the
initial remote config, if the external special remote program requests it.
Also note that IA remotes never use encryption, so encryptionSetup is not
run for them at all, and again the type safety is bypassed.

This leaves two open questions:

1. What to do about S3 and glacier remotes that were set up
   using encryption=pubkey/hybrid with embedcreds?
   Such a git repo has a security hole embedded in it, and this needs to be
   communicated to the user. Is the changelog enough?

2. enableremote won't work in such a repo, because git-annex will
   try to decrypt the embedded creds, which are not encrypted, so fails.
   This needs to be dealt with, especially for ecryption=shared repos,
   which are not really broken, just inconsistently configured.

   Noticing that problem for encryption=shared is what led to commit
   fbdeeeed5f, which tried to
   fix the problem by not decrypting the embedded creds.

This commit was sponsored by Josh Taylor.
2014-09-18 17:26:12 -04:00
http://joeyh.name/
ac635f7ada Added a comment 2014-09-18 19:28:56 +00:00
Joey Hess
4b38a572ab Merge branch 'master' of ssh://git-annex.branchable.com 2014-09-18 15:23:01 -04:00
Joey Hess
d84eab8a8a Revert "S3, Glacier, WebDAV: Fix bug that prevented accessing the creds when the repository was configured with encryption=shared embedcreds=yes."
This reverts commit fbdeeeed5f.

I can find no basis for that commit and think that I made it in error.
setRemoteCredPair always encrypts using the cipher from remoteCipher,
even when the cipher is shared.
2014-09-18 15:21:47 -04:00
http://joeyh.name/
74ad8ebb0c Added a comment 2014-09-18 18:52:17 +00:00
http://joeyh.name/
ce0f2dd114 Added a comment 2014-09-18 18:49:43 +00:00
Joey Hess
2abeae7582 Windows: Avoid crashing trying to list gpg secret keys, for gcrypt which is not yet supported on Windows. 2014-09-16 13:40:44 -04:00
Kim
734c1fa4a3 2014-09-14 22:03:23 +00:00
Joey Hess
632e5aee35 fixed 2014-09-13 16:27:07 -04:00
http://joeyh.name/
ac0945b9d0 Added a comment: turns out to be an upstream bug already filed 2014-09-12 17:46:23 +00:00
http://joeyh.name/
61b75d0475 Added a comment 2014-09-12 16:38:48 +00:00
http://joeyh.name/
6ae36f5445 Added a comment 2014-09-12 16:34:56 +00:00
http://joeyh.name/
db0f679f54 Added a comment 2014-09-12 16:03:09 +00:00
http://grossmeier.net/
cc58b5089c initial 2014-09-12 01:24:47 +00:00