{"thread":{"id":"14888","subject":"Can't get git clone over https with proxy and invalid certificate...","startedAt":"2008-08-08T11:48:24Z","lastAt":"2008-08-08T15:13:30Z","messageCount":3,"participants":["Giovanni Funchal","Shawn O. Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"86492","messageId":"c475e2e60808080448x40683db1wadcd834e94d7d263@mail.gmail.com","threadId":"14888","inReplyTo":null,"subject":"Can't get git clone over https with proxy and invalid certificate...","fromName":"Giovanni Funchal","fromEmail":"gafunchal@gmail.com","sentAt":"2008-08-08T11:48:24Z","receivedAt":"2008-08-08T11:48:24Z","isPatch":false,"sender":{"key":"gafunchal@gmail.com","avatar":"https://gravatar.com/avatar/96f8068bdfb134f61682ec4a9741b71b582efa9d102055028a88643507644e9c?d=mp&s=160"},"body":"Hi all,\n\nI've been trying without success to clone a git repository over https.\nI've got a complicated situation because I have a proxy which only\nallows http/https and the server I'm trying to connect to has an\ninvalid certificate. I'm using git 1.5.6.4 and curl 7.18.1 compiled on\nx86_64.\n\nOk, so I have created the following ~/.curlrc:\n   netrc\n   proxytunnel\n   insecure\n   proxy = http://proxyserver.com:8080\n   proxy-user = proxyuser:proxypassword\n\naccompanied by the following ~/.netrc:\n   machine remoteserver.com\n   login remoteuser\n   password remotepassword\n\nand the following ~/.gitconfig:\n   [user]\n      name = My Name\n      email = my.em@il.com\n   [http]\n      sslVerify = false\n\nAll above files permissions are set to 600 and I have also set the\nenvironment variables http_proxy, https_proxy and all_proxy (one never\nknows) to:\n   http://proxyuser:proxypassword@proxyserver.com:8080\n\nOk, now lets try:\n\n$ wget -q --no-check-certificate\nhttps://remoteuser@remoteserver.com/.git/HEAD && cat HEAD && rm HEAD\nref: refs/heads/master\n$ curl https://remoteuser@remoteserver.com/.git/HEAD\nref: refs/heads/master\n$ git clone https://remoteuser@remoteserver.com/.git/\nInitialized empty Git repository in /home/user/.git/\nerror: Proxy requires authorization!\nwarning: remote HEAD refers to nonexistent ref, unable to checkout.\n\nBoth wget and curl work, but git won't! Any clues?\n\nThanks in advance and best regards,\n-- Giovanni\n"},{"id":"86501","messageId":"20080808142819.GJ28749@spearce.org","threadId":"14888","inReplyTo":"c475e2e60808080448x40683db1wadcd834e94d7d263@mail.gmail.com","subject":"Re: Can't get git clone over https with proxy and invalid certificate...","fromName":"Shawn O. Pearce","fromEmail":"spearce@spearce.org","sentAt":"2008-08-08T14:28:19Z","receivedAt":"2008-08-08T14:28:19Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"Giovanni Funchal <gafunchal@gmail.com> wrote:\n> Ok, so I have created the following ~/.curlrc:\n>    netrc\n>    proxytunnel\n>    insecure\n>    proxy = http://proxyserver.com:8080\n>    proxy-user = proxyuser:proxypassword\n...\n> $ git clone https://remoteuser@remoteserver.com/.git/\n> Initialized empty Git repository in /home/user/.git/\n> error: Proxy requires authorization!\n> warning: remote HEAD refers to nonexistent ref, unable to checkout.\n\nLast time I used Git with an HTTP proxy that required authentication\nI was doing it with an environment variable:\n\n  http_proxy=http://me:pass@proxyserver.com:8080 git clone ...\n\nFortunately this was on a Windows desktop where I was the only\nuser who was logged into the system, so leaking my password into my\nenvironment for a short duration was about the same risk as putting\ninto a ~/. file.\n\n-- \nShawn.\n"},{"id":"86511","messageId":"c475e2e60808080813o4498fc1eu1a08ae05218cec83@mail.gmail.com","threadId":"14888","inReplyTo":"20080808142819.GJ28749@spearce.org","subject":"Re: Can't get git clone over https with proxy and invalid certificate...","fromName":"Giovanni Funchal","fromEmail":"gafunchal@gmail.com","sentAt":"2008-08-08T15:13:30Z","receivedAt":"2008-08-08T15:13:30Z","isPatch":false,"sender":{"key":"gafunchal@gmail.com","avatar":"https://gravatar.com/avatar/96f8068bdfb134f61682ec4a9741b71b582efa9d102055028a88643507644e9c?d=mp&s=160"},"body":"Hello,\n\nWell, turns out that my problem was that my gcc doesn't like the `-R'\nswitch!! Strangely enough, ./configure does not check this!! (one\nshould define Makefile's existing option NO_R_TO_GCC_LINKER)\n\nWhile this seems pretty serious, gcc only shows a tiny message while\ncompiling (\"unrecognized option -R\"), not even a warning, and compiles\nanyway. So if you \"make all install doc install-doc\" like me, you\nwon't see the bug.\n\nI think git build system could be improved somehow to check for that.\nI'll perhaps try to make a patch to this during the weekend.\n\nRegards,\n-- Giovanni\n\nOn Fri, Aug 8, 2008 at 4:28 PM, Shawn O. Pearce <spearce@spearce.org> wrote:\n> Giovanni Funchal <gafunchal@gmail.com> wrote:\n>> Ok, so I have created the following ~/.curlrc:\n>>    netrc\n>>    proxytunnel\n>>    insecure\n>>    proxy = http://proxyserver.com:8080\n>>    proxy-user = proxyuser:proxypassword\n> ...\n>> $ git clone https://remoteuser@remoteserver.com/.git/\n>> Initialized empty Git repository in /home/user/.git/\n>> error: Proxy requires authorization!\n>> warning: remote HEAD refers to nonexistent ref, unable to checkout.\n>\n> Last time I used Git with an HTTP proxy that required authentication\n> I was doing it with an environment variable:\n>\n>  http_proxy=http://me:pass@proxyserver.com:8080 git clone ...\n>\n> Fortunately this was on a Windows desktop where I was the only\n> user who was logged into the system, so leaking my password into my\n> environment for a short duration was about the same risk as putting\n> into a ~/. file.\n>\n> --\n> Shawn.\n>\n"}]}