{"thread":{"id":"21115","subject":"HTTP NTLM Authentication","startedAt":"2009-10-02T17:28:51Z","lastAt":"2009-10-02T19:04:46Z","messageCount":2,"participants":["gsky","Nicholas Miell"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"124140","messageId":"25718488.post@talk.nabble.com","threadId":"21115","inReplyTo":null,"subject":"HTTP NTLM Authentication","fromName":"gsky","fromEmail":"gsky51@gmail.com","sentAt":"2009-10-02T17:28:51Z","receivedAt":"2009-10-02T17:28:51Z","isPatch":false,"sender":{"key":"gsky51@gmail.com","avatar":null},"body":"\nIs is possible for me to pass arguments to the curl calls that git uses to\naccess a repository hosted over HTTP?\n\nI am having a problem accessing the repository as it is authenticated using\nNTLM, I can curl the repository using\n\ncurl --ntlm http://username:pass@machine.domain/git\n\nHow can I do the same for the git clone of the repository?  Is it possible\neasily, or do I have to modify the source and recompile?\n\ngsky\n-- \nView this message in context: http://www.nabble.com/HTTP-NTLM-Authentication-tp25718488p25718488.html\nSent from the git mailing list archive at Nabble.com.\n"},{"id":"124144","messageId":"1254510286-23155-1-git-send-email-nmiell@gmail.com","threadId":"21115","inReplyTo":"25718488.post@talk.nabble.com","subject":"[PATCH] Use the best HTTP authentication method supported by the server","fromName":"Nicholas Miell","fromEmail":"nmiell@gmail.com","sentAt":"2009-10-02T19:04:46Z","receivedAt":"2009-10-02T19:04:46Z","isPatch":true,"sender":{"key":"nmiell@gmail.com","avatar":null},"body":"Currently, libcurl is limited to using HTTP Basic authentication if a\nusername and password are specified. HTTP Basic passes the username\nand password to the server as plaintext, which is obviously\nsuboptimal. Furthermore, some servers are configured to require a more\nsecure authentication method (e.g. Digest or NTLM), which means that\ngit can't talk to them at all.\n\nThis is easily solved by telling libcurl to use any HTTP\nauthentication method it pleases. I leave the decision as to whether\nHTTP Basic (i.e. completely insecure) should be allowed at all to\nsomebody else.  This can be easily changed in the future by using\nCURLAUTH_ANYSAFE instead of CURLAUTH_ANY.\n\nSigned-off-by: Nicholas Miell <nmiell@gmail.com>\n---\n http.c |    1 +\n 1 files changed, 1 insertions(+), 0 deletions(-)\n\nThis passes make test; but I haven't actually tested it on a real\nHTTP server.\n\ndiff --git a/http.c b/http.c\nindex 23b2a19..1937b45 100644\n--- a/http.c\n+++ b/http.c\n@@ -185,6 +185,7 @@ static void init_curl_http_auth(CURL *result)\n \t\tif (!user_pass)\n \t\t\tuser_pass = xstrdup(getpass(\"Password: \"));\n \t\tstrbuf_addf(&up, \"%s:%s\", user_name, user_pass);\n+\t\tcurl_easy_setopt(result, CURLOPT_HTTPAUTH, CURLAUTH_ANY);\n \t\tcurl_easy_setopt(result, CURLOPT_USERPWD,\n \t\t\t\t strbuf_detach(&up, NULL));\n \t}\n-- \n1.6.2.5\n"}]}