Commit graph

23 commits

Author SHA1 Message Date
Joey Hess
eee5bede24
clean up 2015-12-11 11:03:22 -04:00
Joey Hess
49841bbd64 remove unimplennted command-line option from design doc 2015-10-01 12:20:00 -04:00
Joey Hess
f8082933e7 clarify 2013-08-29 14:32:25 -04:00
guilhem
53ce59021a Allow revocation of OpenPGP keys.
/!\ It is to be noted that revoking a key does NOT necessarily prevent
the owner of its private part from accessing data on the remote /!\

The only sound use of `keyid-=` is probably to replace a (sub-)key by
another, where the private part of both is owned by the same
person/entity:

    git annex enableremote myremote keyid-=2512E3C7 keyid+=788A3F4C

Reference: http://git-annex.branchable.com/bugs/Using_a_revoked_GPG_key/

* Other change introduced by this patch:

New keys now need to be added with option `keyid+=`, and the scheme
specified (upon initremote only) with `encryption=`. The motivation for
this change is to open for new schemes, e.g., strict asymmetric
encryption.

    git annex initremote myremote encryption=hybrid keyid=2512E3C7
    git annex enableremote myremote keyid+=788A3F4C
2013-08-29 14:31:33 -04:00
guilhem
00fc21bfec Generate ciphers with a better entropy.
Unless highRandomQuality=false (or --fast) is set, use Libgcypt's
'GCRY_VERY_STRONG_RANDOM' level by default for cipher generation, like
it's done for OpenPGP key generation.

On the assistant side, the random quality is left to the old (lower)
level, in order not to scare the user with an enless page load due to
the blocking PRNG waiting for IO actions.
2013-04-06 16:09:51 -04:00
guilhem
55f0f858ee Allow other MAC algorithms in the Remote Config. 2013-03-29 18:04:52 -04:00
Joey Hess
66580a8b7a fix link 2012-05-23 19:37:22 -04:00
Joey Hess
532ff19aa5 fix link 2011-11-04 15:51:01 -04:00
Joey Hess
b1acf41036 update documentation that mentioned .git-annex/ 2011-06-22 17:26:34 -04:00
Joey Hess
e9815a2eb6 update 2011-05-13 14:56:25 -04:00
Joey Hess
1fdc6b3aad update 2011-05-13 14:55:27 -04:00
Joey Hess
3095e16311 mention that the cipher can also be used to crypt access keys 2011-05-01 14:09:07 -04:00
Joey Hess
83423211a2 design wrapup 2011-04-17 11:27:24 -04:00
Joey Hess
d2e74efdb2 document encryption 2011-04-16 19:35:02 -04:00
Joey Hess
f7018e47e4 typo 2011-04-15 15:09:30 -04:00
https://www.google.com/accounts/o8/id?id=AItOawl9sYlePmv1xK-VvjBdN-5doOa_Xw-jH4U
5bca5733fc typo 2011-04-08 21:51:17 +00:00
Joey Hess
bd1bbc21fa update 2011-04-07 16:05:30 -04:00
Joey Hess
a301a38d99 redundancy 2011-04-05 14:29:44 -04:00
Joey Hess
261b1e6310 update 2011-04-03 15:51:24 -04:00
Joey Hess
0d1f202334 update 2011-04-03 14:53:12 -04:00
Joey Hess
8c9d9eb8af update 2011-04-03 14:47:43 -04:00
Joey Hess
dbe41e667b update 2011-04-03 14:43:38 -04:00
Joey Hess
83acc9ba52 encryption design document 2011-04-03 14:34:00 -04:00