My Quick Notes

Ain't Nobody Got Time to Read

January 9, 2026

Git - Sign commit với GPG key

GPG là gì?

GPG (GNU Privacy Guard) là một công cụ miễn phí dùng để mã hóa, giải mã và ký dữ liệu. Nó đảm bảo giao tiếp an toàn và tính toàn vẹn của dữ liệu thông qua việc sử dụng mật mã khóa công khai (public-key cryptography). GPG thường được sử dụng để:

  • Mã hóa email
  • Ký số phần mềm
  • Truyền tải tệp tin một cách an toàn

Công cụ này được hỗ trợ rộng rãi và tích hợp tốt với nhiều hệ thống, giúp cung cấp bảo mật dữ liệu và xác minh tính xác thực (authenticity) một cách đáng tin cậy.

Sign commit thế nào?

Tạo GPG key

Bỏ qua bước này nếu bạn đã có GPG key.

gpg --full-generate-key

Địa chỉ email nên là địa chỉ mà bạn dùng trên git server như Github hay Gitlab.

Lấy secret key

  • List the long form of the GPG keys for which you have both a public and private key. A private key is required for signing commits or tags. From the list of GPG keys, copy the long form of the GPG key ID you'd like to use. In this example, the GPG key ID is 3AA5C34371567BD2:

    gpg --list-secret-keys --keyid-format=long
    /Users/hubot/.gnupg/secring.gpg
    ------------------------------------
    sec   4096R/3AA5C34371567BD2 2016-03-10 [expires: 2017-03-10]
    uid                          Hubot <hubot@example.com>
    ssb   4096R/4BB6D45482678BE3 2016-03-10
  • If the email in GPG key is already matched with your GitHub/Gitlab account, move to the next step. If not, add your email to your GPG key. Enter gpg --edit-key GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is 3AA5C34371567BD2:

    gpg --edit-key 3AA5C34371567BD2
  • Enter adduid to add the user ID details:

    gpg> adduid
  • Follow the prompts to supply your real name, email address, and any comments. You can modify your entries by choosing N, C, or E:

    Real Name: OCTOCAT
    Email address: "hubot@example.com"
    Comment: GITHUB-KEY
    Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit?
  • Save the changes:

    gpg> save

Add the public key to GitHub/Gitlab

  • Enter gpg --armor --export GPG_key_ID, substituting in the GPG key ID you'd like to use. In the following example, the GPG key ID is 3AA5C34371567BD2:

    gpg --armor --export 3AA5C34371567BD2
    # Prints the GPG key, in ASCII armor format
  • Add your public key to git server:

Commit

Now you can sign when commit with option -S :

git commit -S -m "commit"

or permanent enable in git config:

git config --global commit.gpgSign true  # execute once
git commit -m "commit"
Bài trướcCài đặt local agent trên Raspberry Pi 5 với OpenClaw và Ollama
Bài tiếpNâng cấp Fedora 43 lên Fedora 44

Bình luận