From: "brian m. carlson" <sandals@crustytoothpaste.net>
To: Henning Schild <henning.schild@siemens.com>
Cc: "Jeff King" <peff@peff.net>,
git@vger.kernel.org, "Eric Sunshine" <sunshine@sunshineco.com>,
"Junio C Hamano" <gitster@pobox.com>,
"Martin Ågren" <martin.agren@gmail.com>,
"Ben Toews" <mastahyeti@gmail.com>,
"Taylor Blau" <me@ttaylorr.com>
Subject: Re: [PATCH v2 9/9] gpg-interface t: extend the existing GPG tests with GPGSM
Date: Sat, 14 Jul 2018 18:26:26 +0000 [thread overview]
Message-ID: <20180714182625.GF1042117@genre.crustytoothpaste.net> (raw)
In-Reply-To: <20180711123824.7e0be91a@md1pvb1c.ad001.siemens.net>
[-- Attachment #1: Type: text/plain, Size: 1964 bytes --]
On Wed, Jul 11, 2018 at 12:38:24PM +0200, Henning Schild wrote:
> Am Tue, 10 Jul 2018 13:09:01 -0400
> schrieb Jeff King <peff@peff.net>:
>
> > On Tue, Jul 10, 2018 at 10:52:31AM +0200, Henning Schild wrote:
> >
> > > diff --git a/t/lib-gpg.sh b/t/lib-gpg.sh
> > > index a5d3b2cba..9dcb4e990 100755
> > > --- a/t/lib-gpg.sh
> > > +++ b/t/lib-gpg.sh
> > > @@ -38,7 +38,14 @@ then
> > > "$TEST_DIRECTORY"/lib-gpg/ownertrust &&
> > > gpg --homedir "${GNUPGHOME}" </dev/null >/dev/null
> > > 2>&1 \ --sign -u committer@example.com &&
> > > - test_set_prereq GPG
> > > + test_set_prereq GPG &&
> > > + echo | gpgsm --homedir "${GNUPGHOME}" -o
> > > "$TEST_DIRECTORY"/lib-gpg/gpgsm.crt.user --passphrase-fd 0
> > > --pinentry-mode loopback --generate-key --batch
> > > "$TEST_DIRECTORY"/lib-gpg/gpgsm-gen-key.in &&
> >
> > Is this --generate-key going to require high-quality entropy? That
> > could slow the test suite down (and maybe even stall it quite a bit
> > on servers doing automated CI).
>
> Yes, i also saw that getting "stuck" on one machine. But i blamed an
> experimental kernel.
>
> > Can we save a dummy generated key and just import it? That's what we
> > do for the regular gpg case.
>
> I will look into storing a binary and leaving notes how it was
> generated, just like regular gpg does. The reason i did not do that in
> the first place is that x509 certs have a validity and we introduce
> time into the picture. But i will see if i can generate epoch->infinity
> to get the host clock or just the future out of the picture.
Yeah, I agree that would be good. If gpgsm does anything like what gpg
does, it will require the use of /dev/random, which means this will
definitely be slow on build servers and other noninteractive systems.
We have this problem at $DAYJOB when automating generation of gpg keys.
--
brian m. carlson: Houston, Texas, US
OpenPGP: https://keybase.io/bk2204
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 867 bytes --]
next prev parent reply other threads:[~2018-07-14 18:26 UTC|newest]
Thread overview: 57+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-07-10 8:52 [PATCH v2 0/9] X509 (gpgsm) commit signing support Henning Schild
2018-07-10 8:52 ` [PATCH v2 1/9] builtin/receive-pack: use check_signature from gpg-interface Henning Schild
2018-07-10 8:52 ` [PATCH v2 2/9] gpg-interface: make parse_gpg_output static and remove from interface header Henning Schild
2018-07-10 16:47 ` Junio C Hamano
2018-07-11 8:41 ` Henning Schild
2018-07-10 8:52 ` [PATCH v2 3/9] gpg-interface: add new config to select how to sign a commit Henning Schild
2018-07-10 15:56 ` Jeff King
2018-07-10 8:52 ` [PATCH v2 4/9] t/t7510: check the validation of the new config gpg.format Henning Schild
2018-07-10 15:55 ` Jeff King
2018-07-11 8:02 ` Henning Schild
2018-07-10 16:54 ` Junio C Hamano
2018-07-11 8:47 ` Henning Schild
2018-07-10 8:52 ` [PATCH v2 5/9] gpg-interface: introduce an abstraction for multiple gpg formats Henning Schild
2018-07-10 16:23 ` Jeff King
2018-07-13 8:41 ` Henning Schild
2018-07-10 17:16 ` Junio C Hamano
2018-07-13 8:41 ` Henning Schild
2018-07-10 8:52 ` [PATCH v2 6/9] gpg-interface: do not hardcode the key string len anymore Henning Schild
2018-07-10 15:49 ` Jeff King
2018-07-11 8:54 ` Henning Schild
2018-07-11 12:34 ` Jeff King
2018-07-11 13:46 ` Henning Schild
2018-07-11 14:27 ` Jeff King
2018-07-11 16:15 ` Henning Schild
2018-07-11 16:38 ` Jeff King
2018-07-10 8:52 ` [PATCH v2 7/9] gpg-interface: introduce new config to select per gpg format program Henning Schild
2018-07-10 16:54 ` Jeff King
2018-07-10 16:56 ` Jeff King
2018-07-14 18:13 ` brian m. carlson
2018-07-16 21:35 ` Jeff King
2018-07-16 21:56 ` Junio C Hamano
2018-07-16 22:23 ` Jeff King
2018-07-16 23:12 ` Junio C Hamano
2018-07-10 17:29 ` Junio C Hamano
2018-07-13 8:41 ` Henning Schild
2018-07-10 8:52 ` [PATCH v2 8/9] gpg-interface: introduce new signature format "x509" using gpgsm Henning Schild
2018-07-10 17:01 ` Jeff King
2018-07-10 17:40 ` Junio C Hamano
2018-07-10 17:50 ` Jeff King
2018-07-11 9:18 ` Henning Schild
2018-07-10 8:52 ` [PATCH v2 9/9] gpg-interface t: extend the existing GPG tests with GPGSM Henning Schild
2018-07-10 17:09 ` Jeff King
2018-07-10 17:16 ` Jeff King
2018-07-11 10:38 ` Henning Schild
2018-07-11 12:51 ` Jeff King
2018-07-11 13:40 ` Henning Schild
2018-07-11 14:35 ` Jeff King
2018-07-11 15:48 ` Henning Schild
2018-07-11 16:26 ` Junio C Hamano
2018-07-14 18:26 ` brian m. carlson [this message]
2018-07-10 21:12 ` Junio C Hamano
2018-07-11 10:38 ` Henning Schild
2018-07-11 14:33 ` Jeff King
2018-07-11 16:35 ` Henning Schild
2018-07-10 17:12 ` [PATCH v2 0/9] X509 (gpgsm) commit signing support Jeff King
2018-07-14 18:33 ` brian m. carlson
2018-07-16 21:32 ` Jeff King
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: http://vger.kernel.org/majordomo-info.html
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180714182625.GF1042117@genre.crustytoothpaste.net \
--to=sandals@crustytoothpaste.net \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=henning.schild@siemens.com \
--cc=martin.agren@gmail.com \
--cc=mastahyeti@gmail.com \
--cc=me@ttaylorr.com \
--cc=peff@peff.net \
--cc=sunshine@sunshineco.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://80x24.org/mirrors/git.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).