ssh key

Alexandre Oliva aoliva@redhat.com
Tue Aug 10 17:28:00 GMT 2004


On Aug  9, 2004, Christopher Faylor <me@cgf.cx> wrote:

> On Mon, Aug 09, 2004 at 04:37:43AM -0300, Alexandre Oliva wrote:
>> On Aug  7, 2004, Christopher Faylor <me@cgf.cx> wrote:
>>> On Sat, Aug 07, 2004 at 12:02:40PM -0400, James A.  Morrison wrote:
>>>> I would like the following ssh key added for my access to the GCC
>>>> repository.  My usersname is phython.
>> 
>>> I've added the key.  You should be all set.
>> 
>> Am I the only one who thinks `hey, could you grant this key access to
>> my account' e-mail requests should get some additional form of
>> verification than simply hoping they weren't forged by a random third
>> party trying to get unwarranted access to s.r.c?

> Since he only has CVS access and the email headers seemed to check out,
> I didn't think there was great harm in satisfying the request.

Oh, absolutely.  I'm just thinking it might be reasonable to have, as
part of the sign-up procedure, a gpg pubkey registration, and demand
such requests to be signed with the corresponding privkey.

-- 
Alexandre Oliva             http://www.ic.unicamp.br/~oliva/
Red Hat Compiler Engineer   aoliva@{redhat.com, gcc.gnu.org}
Free Software Evangelist  oliva@{lsd.ic.unicamp.br, gnu.org}



More information about the Overseers mailing list