You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

git-remote-gcrypt多参与者协作解密失败问题解决方案咨询

多参与者使用git-remote-gcrypt协作的解密问题解决方法

问题场景

我正在学习用git-remote-gcrypt进行多参与者协作,用两台电脑模拟两个用户,执行了以下操作:

  1. 分别为两台电脑生成GPG密钥对:
    • Computer0:密钥对usr0@00.com,指纹xxxx0000xxxx
    • Computer1:密钥对usr1@11.com,指纹yyyy1111yyyy
  2. 交换公钥:将双方公钥导入到对方的GPG信任数据库
  3. 在GitHub创建空仓库,地址为git@github.com:leon/testgcrypt.git
  4. 在Computer0创建本地仓库并提交内容:
    mkdir testgcrypt && cd testgcrypt && git init
    echo "content0" > content0.txt
    git add -- . && git commit -m "0.0.0 content0"
    
  5. 在Computer0配置远程仓库并推送:
    git remote add github gcrypt::git@github.com:leon/testgcrypt.git
    git config remote.github.gcrypt-participants xxxx0000xxxx yyyy1111yyyy
    git branch --set-upstream github/master master
    git push
    
  6. 在Computer1配置并尝试拉取:
    mkdir testgcrypt && cd testgcrypt && git init
    git remote add github gcrypt::git@github.com:leon/testgcrypt.git
    git config remote.github.gcrypt-participants xxxx0000xxxx yyyy1111yyyy
    git pull github master
    

错误信息

执行拉取时遇到以下错误:

gcrypt: Decrypting manifest
gpg: error getting version from 'scdaemon': No SmartCard daemon
gpg: decryption failed: No secret key
gcrypt: Failed to decrypt manifest!

原因分析

核心问题有两个:

  1. 密钥信任未配置:导入对方公钥后未设置足够的信任级别,导致GPG拒绝使用这些密钥进行加密/解密操作,首次推送时仅用了Computer0自己的公钥加密数据,Computer1没有对应私钥无法解密。
  2. 加密逻辑误解:公钥仅用于加密数据,解密必须使用自己的私钥——git-remote-gcrypt会用所有参与者的公钥加密内容,每个参与者用自己的私钥解密,而非用对方公钥解密。

解决步骤

1. 配置双方密钥信任

在两台电脑上分别对导入的对方公钥设置最终信任:

# Computer0上操作:信任user1的公钥
gpg --edit-key yyyy1111yyyy
# 交互模式下输入:trust → 选择5(最终信任)→ 输入quit保存
# Computer1上操作:信任user0的公钥
gpg --edit-key xxxx0000xxxx
# 交互模式下输入:trust → 选择5(最终信任)→ 输入quit保存

2. 重新推送加密仓库(Computer0)

首次推送时未正确用所有参与者公钥加密,需重新推送:

cd testgcrypt
# 清空远程现有分支(若已存在)
git push github :master
# 重新推送,确保用所有参与者公钥加密
git push github master

3. Computer1重新拉取

删除之前的错误本地仓库,重新初始化拉取:

rm -rf testgcrypt
mkdir testgcrypt && cd testgcrypt
git init
git remote add github gcrypt::git@github.com:leon/testgcrypt.git
git config remote.github.gcrypt-participants xxxx0000xxxx yyyy1111yyyy
git pull github master

关键注意事项

  • git-remote-gcrypt推送时,会自动用gcrypt-participants列表中所有公钥加密仓库内容,确保每个参与者都能用自己的私钥解密。
  • 必须确保导入的外部公钥被设置为可信,否则GPG会忽略这些密钥,导致加密范围不完整。
  • 错误提示中的“No secret key”并非指缺少对方私钥,而是GPG找不到可用于解密的本地可信私钥,或密钥信任不足导致无法识别解密路径。

内容的提问来源于stack exchange,提问作者Leon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 13:53:16