{"thread":{"id":"1949","subject":"[PATCH 1/3] Support for SSL client cert","startedAt":"2005-09-26T17:51:57Z","lastAt":"2005-09-28T20:22:13Z","messageCount":12,"participants":["Nick Hengeveld","Petr Baudis","Junio C Hamano","Ameer Armaly","Daniel Barkalow","Catalin Marinas","Mariano Videla","Vincent Hanquez","Matthias Urlichs"],"isPatch":true,"patchVersion":1,"patchTotal":3},"messages":[{"id":"9306","messageId":"20050926175156.GB9410@reactrix.com","threadId":"1949","inReplyTo":null,"subject":"[PATCH 1/3] Support for SSL client cert","fromName":"Nick Hengeveld","fromEmail":"nickh@reactrix.com","sentAt":"2005-09-26T17:51:57Z","receivedAt":"2005-09-26T17:51:57Z","isPatch":true,"sender":{"key":"nickh@reactrix.com","avatar":null},"body":"\nAdded SSL client args and CURL settings\n\nSigned-off-by: Nick Hengeveld <nickh@reactrix.com>\n\n\n---\n\n http-fetch.c |   28 +++++++++++++++++++++++++++-\n 1 files changed, 27 insertions(+), 1 deletions(-)\n\n2d293c34fdfde8a394b5f8a5c5343d9caf363bcc\ndiff --git a/http-fetch.c b/http-fetch.c\n--- a/http-fetch.c\n+++ b/http-fetch.c\n@@ -476,6 +476,10 @@ int main(int argc, char **argv)\n \tchar *commit_id;\n \tchar *url;\n \tint arg = 1;\n+\tchar *ssl_cert = NULL;\n+\tchar *ssl_key = NULL;\n+\tchar *ssl_capath = NULL;\n+\tchar *ssl_cacert = NULL;\n \n \twhile (arg < argc && argv[arg][0] == '-') {\n \t\tif (argv[arg][1] == 't') {\n@@ -491,11 +495,19 @@ int main(int argc, char **argv)\n \t\t} else if (argv[arg][1] == 'w') {\n \t\t\twrite_ref = argv[arg + 1];\n \t\t\targ++;\n+\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--cert\")) {\n+\t\t\tssl_cert = argv[++arg];\n+\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--key\")) {\n+\t\t\tssl_key = argv[++arg];\n+\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--capath\")) {\n+\t\t\tssl_capath = argv[++arg];\n+\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--cacert\")) {\n+\t\t\tssl_cacert = argv[++arg];\n \t\t}\n \t\targ++;\n \t}\n \tif (argc < arg + 2) {\n-\t\tusage(\"git-http-fetch [-c] [-t] [-a] [-d] [-v] [--recover] [-w ref] commit-id url\");\n+\t\tusage(\"git-http-fetch [-c] [-t] [-a] [-d] [-v] [--recover] [-w ref] [--cert ssl-cert-file] [--key ssl-key-file] [--capath CA-dir] [--cacert CA-cert-file] commit-id url\");\n \t\treturn 1;\n \t}\n \tcommit_id = argv[arg];\n@@ -506,6 +518,20 @@ int main(int argc, char **argv)\n \tcurl = curl_easy_init();\n \tno_pragma_header = curl_slist_append(no_pragma_header, \"Pragma:\");\n \n+        /* Set SSL parameters if they were provided */\n+\tif (ssl_cert != NULL) {\n+\t\tcurl_easy_setopt(curl, CURLOPT_SSLCERT, ssl_cert);\n+\t}\n+\tif (ssl_key != NULL) {\n+\t\tcurl_easy_setopt(curl, CURLOPT_SSLKEY, ssl_key);\n+\t}\n+\tif (ssl_capath != NULL) {\n+\t\tcurl_easy_setopt(curl, CURLOPT_CAPATH, ssl_capath);\n+\t}\n+\tif (ssl_cacert != NULL) {\n+\t\tcurl_easy_setopt(curl, CURLOPT_CAINFO, ssl_cacert);\n+\t}\n+\n \tcurl_ssl_verify = getenv(\"GIT_SSL_NO_VERIFY\") ? 0 : 1;\n \tcurl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);\n #if LIBCURL_VERSION_NUM >= 0x070907\n"},{"id":"9312","messageId":"20050926182341.GA26340@pasky.or.cz","threadId":"1949","inReplyTo":"20050926175156.GB9410@reactrix.com","subject":"Re: [PATCH 1/3] Support for SSL client cert","fromName":"Petr Baudis","fromEmail":"pasky@suse.cz","sentAt":"2005-09-26T18:23:41Z","receivedAt":"2005-09-26T18:23:41Z","isPatch":true,"sender":{"key":"pasky@ucw.cz","avatar":"https://avatars.githubusercontent.com/u/18439?v=4"},"body":"Dear diary, on Mon, Sep 26, 2005 at 07:51:57PM CEST, I got a letter\nwhere Nick Hengeveld <nickh@reactrix.com> told me that...\n> @@ -491,11 +495,19 @@ int main(int argc, char **argv)\n>  \t\t} else if (argv[arg][1] == 'w') {\n>  \t\t\twrite_ref = argv[arg + 1];\n>  \t\t\targ++;\n> +\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--cert\")) {\n> +\t\t\tssl_cert = argv[++arg];\n> +\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--key\")) {\n> +\t\t\tssl_key = argv[++arg];\n> +\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--capath\")) {\n> +\t\t\tssl_capath = argv[++arg];\n> +\t\t} else if (arg+1 < argc && !strcmp(argv[arg], \"--cacert\")) {\n> +\t\t\tssl_cacert = argv[++arg];\n>  \t\t}\n>  \t\targ++;\n>  \t}\n>  \tif (argc < arg + 2) {\n> -\t\tusage(\"git-http-fetch [-c] [-t] [-a] [-d] [-v] [--recover] [-w ref] commit-id url\");\n> +\t\tusage(\"git-http-fetch [-c] [-t] [-a] [-d] [-v] [--recover] [-w ref] [--cert ssl-cert-file] [--key ssl-key-file] [--capath CA-dir] [--cacert CA-cert-file] commit-id url\");\n>  \t\treturn 1;\n>  \t}\n>  \tcommit_id = argv[arg];\n\nCould we please have at least --sslkey, if not having 'ssl' prepended to\nall of them? You never know when you'll want to call something else like\nthat in the future... ;-)\n\n-- \n\t\t\t\tPetr \"Pasky\" Baudis\nStuff: http://pasky.or.cz/\nVI has two modes: the one in which it beeps and the one in which\nit doesn't.\n"},{"id":"9313","messageId":"20050926183617.GA11382@reactrix.com","threadId":"1949","inReplyTo":"20050926182341.GA26340@pasky.or.cz","subject":"Re: [PATCH 1/3] Support for SSL client cert","fromName":"Nick Hengeveld","fromEmail":"nickh@reactrix.com","sentAt":"2005-09-26T18:36:18Z","receivedAt":"2005-09-26T18:36:18Z","isPatch":true,"sender":{"key":"nickh@reactrix.com","avatar":null},"body":"On Mon, Sep 26, 2005 at 08:23:41PM +0200, Petr Baudis wrote:\n\n> Could we please have at least --sslkey, if not having 'ssl' prepended to\n> all of them? You never know when you'll want to call something else like\n> that in the future... ;-)\n\nMakes sense - I wasn't comfortable deciding what those parameters should be\nso I used the curl command-line options.  Who gets to make the official\ncall on that?\n\n-- \nFor a successful technology, reality must take precedence over public\nrelations, for nature cannot be fooled.\n"},{"id":"9325","messageId":"7v3bnrh85g.fsf@assigned-by-dhcp.cox.net","threadId":"1949","inReplyTo":"20050926182341.GA26340@pasky.or.cz","subject":"Re: [PATCH 1/3] Support for SSL client cert","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-09-26T20:43:39Z","receivedAt":"2005-09-26T20:43:39Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Petr Baudis <pasky@suse.cz> writes:\n\n> Could we please have at least --sslkey, if not having 'ssl' prepended to\n> all of them? You never know when you'll want to call something else like\n> that in the future... ;-)\n\nThat is a valid concern.\n\nAnoter possibility is to read them from the environment, since\nwe already do SSL_NO_VERIFY from there.\n\nIf we go that route, it might make sense to have something like\nthe following in .git/remotes/that-site file:\n\n    URL: https://some.company.site.xz\n    ENV: GIT_SSL_KEY='/home/user/.ssl/'My ssl key'\n    ENV: GIT_SSL_CERT='/home/user/.ssl/certs/My Certificate'\n    ENV: GIT_SSL_CAPATH='/home/user/.ssl/My CA'\n    ...\n\nthen at the beginning of git-fetch, we could eval these ENV\nlines.\n"},{"id":"9350","messageId":"20050927001542.GC15615@reactrix.com","threadId":"1949","inReplyTo":"7v3bnrh85g.fsf@assigned-by-dhcp.cox.net","subject":"Re: [PATCH 1/3] Support for SSL client cert","fromName":"Nick Hengeveld","fromEmail":"nickh@reactrix.com","sentAt":"2005-09-27T00:15:42Z","receivedAt":"2005-09-27T00:15:42Z","isPatch":true,"sender":{"key":"nickh@reactrix.com","avatar":null},"body":"On Mon, Sep 26, 2005 at 01:43:39PM -0700, Junio C Hamano wrote:\n\n> That is a valid concern.\n> \n> Anoter possibility is to read them from the environment, since\n> we already do SSL_NO_VERIFY from there.\n\nGood point - use of environment variables is more consistent.  Use of\ncommand-line arguments is a bit more convenient in my case since I'm\ndriving the transfer from a perl script, but I suppose consistency is\nmore important...\n\n-- \nFor a successful technology, reality must take precedence over public\nrelations, for nature cannot be fooled.\n"},{"id":"9351","messageId":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","threadId":"1949","inReplyTo":"20050927001542.GC15615@reactrix.com","subject":"More Porcelains?","fromName":"Junio C Hamano","fromEmail":"junkio@cox.net","sentAt":"2005-09-27T00:43:46Z","receivedAt":"2005-09-27T00:43:46Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Nick Hengeveld <nickh@reactrix.com> writes:\n\n> Good point - use of environment variables is more consistent.  Use of\n> command-line arguments is a bit more convenient in my case since I'm\n> driving the transfer from a perl script, but I suppose consistency is\n> more important...\n\nNow you made me curious.\n\nHow many of you are working on your own Porcelains, announced or\nunannounced?  I know about Cogito and StGIT ;-).  In a distant\npast I have heard of something called JIT but I think it is now\ndefunct.  Matthias Urlichs said he is doing something with\nPython.  Anybody else?\n"},{"id":"9352","messageId":"000a01c5c2fe$71fd6200$0200a8c0@AMEER","threadId":"1949","inReplyTo":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","subject":"Re: More Porcelains?","fromName":"Ameer Armaly","fromEmail":"ameerarmaly@bellsouth.net","sentAt":"2005-09-27T00:57:33Z","receivedAt":"2005-09-27T00:57:33Z","isPatch":false,"sender":{"key":"ameerarmaly@bellsouth.net","avatar":null},"body":"\n----- Original Message ----- \nFrom: \"Junio C Hamano\" <junkio@cox.net>\nTo: <git@vger.kernel.org>\nCc: \"Nick Hengeveld\" <nickh@reactrix.com>\nSent: Monday, September 26, 2005 8:43 PM\nSubject: More Porcelains?\n\n\n> Nick Hengeveld <nickh@reactrix.com> writes:\n>\n>> Good point - use of environment variables is more consistent.  Use of\n>> command-line arguments is a bit more convenient in my case since I'm\n>> driving the transfer from a perl script, but I suppose consistency is\n>> more important...\n>\n> Now you made me curious.\n>\n> How many of you are working on your own Porcelains, announced or\n> unannounced?  I know about Cogito and StGIT ;-).  In a distant\n> past I have heard of something called JIT but I think it is now\n> defunct.  Matthias Urlichs said he is doing something with\n> Python.  Anybody else?\n>\nI am seriously looking at putting one together in the D language \n(http://www.digitalmars.com/d) <plug>, though it doesn't actually do \nanything as of yet, since I have to balance classes along with it.\n>\n> -\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html \n"},{"id":"9365","messageId":"Pine.LNX.4.63.0509270132370.23242@iabervon.org","threadId":"1949","inReplyTo":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","subject":"Re: More Porcelains?","fromName":"Daniel Barkalow","fromEmail":"barkalow@iabervon.org","sentAt":"2005-09-27T06:15:06Z","receivedAt":"2005-09-27T06:15:06Z","isPatch":false,"sender":{"key":"barkalow@iabervon.org","avatar":"https://avatars.githubusercontent.com/u/55364219?v=4"},"body":"On Mon, 26 Sep 2005, Junio C Hamano wrote:\n\n> How many of you are working on your own Porcelains, announced or\n> unannounced?\n\nI don't have a porcelain, but I organize my working trees/repository in a \nnon-standard way, using an additional script (which creates a new working \ntree linked to an existing repository). \n\nI've also got a set of scripts for splitting up a patch into a series, \nwhich I've still not gotten around to cleaning up and submitting.\n\nFor the way I structure my working trees, it would be really helpful if \nall of the miscellaneous things that should stay with a repository (such \nas remotes) were in a single subdirectory of .git, so that I could just \nhave a third symlink and have it all work, rather than needing a bunch of \nadditional links.\n\n\t-Daniel\n*This .sig left intentionally blank*\n"},{"id":"9373","messageId":"tnxll1jvsc8.fsf@arm.com","threadId":"1949","inReplyTo":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","subject":"Re: More Porcelains?","fromName":"Catalin Marinas","fromEmail":"catalin.marinas@gmail.com","sentAt":"2005-09-27T08:16:07Z","receivedAt":"2005-09-27T08:16:07Z","isPatch":false,"sender":{"key":"catalin.marinas@gmail.com","avatar":null},"body":"Junio C Hamano <junkio@cox.net> wrote:\n> How many of you are working on your own Porcelains, announced or\n> unannounced?  I know about Cogito and StGIT ;-).  In a distant\n> past I have heard of something called JIT but I think it is now\n> defunct.  Matthias Urlichs said he is doing something with\n> Python.  Anybody else?\n\nI just found gipy on sf.net - http://sourceforge.net/projects/gipy.\n\nThere are no files uploaded yet but hopefully I can soon 'steal' some\ncode for StGIT ;-)\n\n-- \nCatalin\n"},{"id":"9398","messageId":"1127840572.16026.29.camel@mariano","threadId":"1949","inReplyTo":"tnxll1jvsc8.fsf@arm.com","subject":"Re: More Porcelains?","fromName":"Mariano Videla","fromEmail":"mvidela@ases.com.ar","sentAt":"2005-09-27T17:02:51Z","receivedAt":"2005-09-27T17:02:51Z","isPatch":false,"sender":{"key":"mvidela@ases.com.ar","avatar":null},"body":"Mmm...It's no porcelain.\n\nI setup a git repository for gipy... Didn't upload any files in\nsourceforge because I don't think is ready.\n\nhttp://24.232.198.9:7978/gipy.git\nhttp://24.232.198.9:7978/cgi/gitweb.cgi\n\nBy the way... you can 'steel' it all!\n\nMariano\n\nOn mar, 2005-09-27 at 09:16 +0100, Catalin Marinas wrote:\n> Junio C Hamano <junkio@cox.net> wrote:\n> > How many of you are working on your own Porcelains, announced or\n> > unannounced?  I know about Cogito and StGIT ;-).  In a distant\n> > past I have heard of something called JIT but I think it is now\n> > defunct.  Matthias Urlichs said he is doing something with\n> > Python.  Anybody else?\n> \n> I just found gipy on sf.net - http://sourceforge.net/projects/gipy.\n> \n> There are no files uploaded yet but hopefully I can soon 'steal' some\n> code for StGIT ;-)\n> \n"},{"id":"9419","messageId":"20050928113008.GA11309@snarc.org","threadId":"1949","inReplyTo":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","subject":"Re: More Porcelains?","fromName":"Vincent Hanquez","fromEmail":"tab@snarc.org","sentAt":"2005-09-28T11:30:08Z","receivedAt":"2005-09-28T11:30:08Z","isPatch":false,"sender":{"key":"tab@snarc.org","avatar":"https://gravatar.com/avatar/f639df78e7af804fd54c86e32a2b7b1853d3765ba8e66f878e24c933efc30a2a?d=mp&s=160"},"body":"On Mon, Sep 26, 2005 at 05:43:46PM -0700, Junio C Hamano wrote:\n> Now you made me curious.\n> \n> How many of you are working on your own Porcelains, announced or\n> unannounced?  I know about Cogito and StGIT ;-).  In a distant\n> past I have heard of something called JIT but I think it is now\n> defunct.  Matthias Urlichs said he is doing something with\n> Python.  Anybody else?\n\nHi Junio,\n\nWell, I kinda work on one written in C using a libgit (using exec of git\nexecutable for the moment) It doesn't do that much at the moment:\ncommiting, adding files, removing files.\n\nAt some point I'ld like to have a very integrated and easy to use\nporcelain, but for now that's more a learning git by practice kind of\nproject.\n\nCheers,\n-- \nVincent Hanquez\n"},{"id":"9441","messageId":"pan.2005.09.28.20.22.10.626793@smurf.noris.de","threadId":"1949","inReplyTo":"7v64sn8hml.fsf_-_@assigned-by-dhcp.cox.net","subject":"Re: More Porcelains?","fromName":"Matthias Urlichs","fromEmail":"smurf@smurf.noris.de","sentAt":"2005-09-28T20:22:13Z","receivedAt":"2005-09-28T20:22:13Z","isPatch":false,"sender":{"key":"matthias@urlichs.de","avatar":"https://gravatar.com/avatar/2708905af227313eba6f2b2ae0f7d0259b5ac5d71baef58fe5a13c699ce0bbf0?d=mp&s=160"},"body":"Hi, Junio C Hamano wrote:\n\n> Matthias Urlichs said he is doing something with Python\n\nPython integration needs either lots of fork+exec, a git rewrite in\nPython, or a libgit reorganization in library-ized C.\n\nI'm doing the latter, but my free time is kindof limited for now.\n\nMy library-ize branch is at \n\tgit fetch http://netz.smurf.noris.de/git/git.git libize\nif anybody wants to have a look. My first goal is to get object access\nworking sanely (because that's what I need for my Python project).\n\nI haven't merged up for some time, though.\n\n-- \nMatthias Urlichs   |   {M:U} IT Design @ m-u-it.de   |  smurf@smurf.noris.de\nDisclaimer: The quote was selected randomly. Really. | http://smurf.noris.de\n - -\nPaul's Law:\n\tIn America, it's not how much an item costs, it's how much you save.\n"}]}