<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dear Lazyweb: Why don&#8217;t public ssh repository sites like me?</title>
	<atom:link href="http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/</link>
	<description>Just another GNOME Blogs weblog</description>
	<lastBuildDate>Sun, 11 Jan 2009 23:03:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Elijah</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-321</link>
		<dc:creator>Elijah</dc:creator>
		<pubDate>Wed, 24 Sep 2008 20:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-321</guid>
		<description>Thanks everyone for the suggestions.  My dsa key was generated on rhel4 (yeah, yeah, I don&#039;t like it either--corporate redtape prevents an upgrade to something recent), so not affected by the debian/ubuntu openssh debacle.

Jakub: Yeah, I suspect I just emailed Petr when he was gone on vacation.  Probably just bad timing on my part.  I should have sent another email, but anyway, Adam G has solved the issue for me.</description>
		<content:encoded><![CDATA[<p>Thanks everyone for the suggestions.  My dsa key was generated on rhel4 (yeah, yeah, I don&#8217;t like it either&#8211;corporate redtape prevents an upgrade to something recent), so not affected by the debian/ubuntu openssh debacle.</p>
<p>Jakub: Yeah, I suspect I just emailed Petr when he was gone on vacation.  Probably just bad timing on my part.  I should have sent another email, but anyway, Adam G has solved the issue for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jakub Narebski</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-320</link>
		<dc:creator>Jakub Narebski</dc:creator>
		<pubDate>Wed, 24 Sep 2008 17:19:14 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-320</guid>
		<description>First, I had no problems with repo.or.cz, and author and maintainer (Petr Baudis) is usually responsive. I can push to repo.or.cz without problems; alternatively you can set repository on repo.or.cz to mirror your repository instead, by polling periodically (but I haven&#039;t used this setup personally).

I used ssh-keygen to generate key, copied to ~/.ssh, pasted public key on repo.or.cz (the *.pub file; I don&#039;t know, perhaps now it can be simply uploaded). Then I use ssh-add to add a key (using absolute pathname), enter passphrase, check that key is in the ring using &quot;ssh-add -l&quot;... and &quot;gut push repo&quot; works. BTW. I have keychain installed and in .profile, and it starts ssh-agent for me...</description>
		<content:encoded><![CDATA[<p>First, I had no problems with repo.or.cz, and author and maintainer (Petr Baudis) is usually responsive. I can push to repo.or.cz without problems; alternatively you can set repository on repo.or.cz to mirror your repository instead, by polling periodically (but I haven&#8217;t used this setup personally).</p>
<p>I used ssh-keygen to generate key, copied to ~/.ssh, pasted public key on repo.or.cz (the *.pub file; I don&#8217;t know, perhaps now it can be simply uploaded). Then I use ssh-add to add a key (using absolute pathname), enter passphrase, check that key is in the ring using &#8220;ssh-add -l&#8221;&#8230; and &#8220;gut push repo&#8221; works. BTW. I have keychain installed and in .profile, and it starts ssh-agent for me&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam G</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-319</link>
		<dc:creator>Adam G</dc:creator>
		<pubDate>Wed, 24 Sep 2008 15:48:20 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-319</guid>
		<description>You need to ssh to git@gitorious.org, not @gitorious.org</description>
		<content:encoded><![CDATA[<p>You need to ssh to <a href="mailto:git@gitorious.org">git@gitorious.org</a>, not @gitorious.org</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bkor</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-318</link>
		<dc:creator>bkor</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:44:17 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-318</guid>
		<description>Remi and ajax:

debug1: Offering public key: /home/newren/.ssh/gitorious

it already is configured.</description>
		<content:encoded><![CDATA[<p>Remi and ajax:</p>
<p>debug1: Offering public key: /home/newren/.ssh/gitorious</p>
<p>it already is configured.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy Wingo</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-317</link>
		<dc:creator>Andy Wingo</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-317</guid>
		<description>You&#039;ve probably checked, but perhaps those keys are DSA keys -- many servers silently reject DSA keys these days, as they are less secure than RSA, compounded with the Debian OpenSSH debacle.</description>
		<content:encoded><![CDATA[<p>You&#8217;ve probably checked, but perhaps those keys are DSA keys &#8212; many servers silently reject DSA keys these days, as they are less secure than RSA, compounded with the Debian OpenSSH debacle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: smcv</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-313</link>
		<dc:creator>smcv</dc:creator>
		<pubDate>Wed, 24 Sep 2008 14:11:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-313</guid>
		<description>Some sites (notably Debian and freedesktop.org) don&#039;t accept DSA keys, because of the Debian OpenSSL PRNG vulnerability (an RSA key is vulnerable if it was *generated* on a vulnerable system, which can be detected; a DSA key is vulnerable if it was ever *used* on a vulnerable system, which can&#039;t).</description>
		<content:encoded><![CDATA[<p>Some sites (notably Debian and freedesktop.org) don&#8217;t accept DSA keys, because of the Debian OpenSSL PRNG vulnerability (an RSA key is vulnerable if it was *generated* on a vulnerable system, which can be detected; a DSA key is vulnerable if it was ever *used* on a vulnerable system, which can&#8217;t).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ajax</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-312</link>
		<dc:creator>ajax</dc:creator>
		<pubDate>Wed, 24 Sep 2008 13:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-312</guid>
		<description>Since your gitorious key pair is apparently not your normal key pair, you need to add the private key to an IdentityFile line in ~/.ssh/config, otherwise ssh won&#039;t know to look at it.  See &#039;man ssh_config&#039; for details.</description>
		<content:encoded><![CDATA[<p>Since your gitorious key pair is apparently not your normal key pair, you need to add the private key to an IdentityFile line in ~/.ssh/config, otherwise ssh won&#8217;t know to look at it.  See &#8216;man ssh_config&#8217; for details.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jani Monoses</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-311</link>
		<dc:creator>Jani Monoses</dc:creator>
		<pubDate>Wed, 24 Sep 2008 13:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-311</guid>
		<description>Maybe your homedir permissions on gitorious are not 0755 ?</description>
		<content:encoded><![CDATA[<p>Maybe your homedir permissions on gitorious are not 0755 ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Banck</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-310</link>
		<dc:creator>Michael Banck</dc:creator>
		<pubDate>Wed, 24 Sep 2008 13:05:57 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-310</guid>
		<description>Maybe their sshd does not accept DSA keys anymore (since the Debian openssl debacle), while their frontend still happily accepts them.

It is recommended to use RSA keys these days anyways (although a lot of default code/command snippets still use id_dsa etc. as examples)</description>
		<content:encoded><![CDATA[<p>Maybe their sshd does not accept DSA keys anymore (since the Debian openssl debacle), while their frontend still happily accepts them.</p>
<p>It is recommended to use RSA keys these days anyways (although a lot of default code/command snippets still use id_dsa etc. as examples)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rémi Cardona</title>
		<link>http://blogs.gnome.org/newren/2008/09/24/dear-lazyweb-why-dont-public-ssh-repository-sites-like-me/comment-page-1/#comment-309</link>
		<dc:creator>Rémi Cardona</dc:creator>
		<pubDate>Wed, 24 Sep 2008 13:04:07 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.gnome.org/newren/?p=129#comment-309</guid>
		<description>You might want to do &quot;ssh-add ~/.ssh/gitorious&quot; (you&#039;ll need ssh-agent running) before your first pull/push to gitorious.

That should help</description>
		<content:encoded><![CDATA[<p>You might want to do &#8220;ssh-add ~/.ssh/gitorious&#8221; (you&#8217;ll need ssh-agent running) before your first pull/push to gitorious.</p>
<p>That should help</p>
]]></content:encoded>
	</item>
</channel>
</rss>
