{"thread":{"id":"29929","subject":"CAC enabled authentication with git transfer protocols","startedAt":"2012-03-13T00:54:41Z","lastAt":"2012-03-13T02:20:39Z","messageCount":3,"participants":["Jones, Brian P CTR SPAWARSYSCEN-PACIFIC, 63600","Shawn Pearce","Chris Kees"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"186802","messageId":"B1ECBDB2E23847488F70D870CBE563F70198D579@nawespscez06v.nadsuswe.nads.navy.mil","threadId":"29929","inReplyTo":null,"subject":"CAC enabled authentication with git transfer protocols","fromName":"Jones, Brian P CTR SPAWARSYSCEN-PACIFIC, 63600","fromEmail":"brian.p.jones4.ctr@navy.mil","sentAt":"2012-03-13T00:54:41Z","receivedAt":"2012-03-13T00:54:41Z","isPatch":false,"sender":{"key":"brian.p.jones4.ctr@navy.mil","avatar":null},"body":"Does anyone know if git is being used in a military CAC enabled environment? This means that the DoD CAC card is required to authenticate when hitting the git transfer protocol. This is a requirement before I can propose using git. I understand that git is able to use https as well as ssh or over port 9418. Is there any documentation on setting up CAC enabled git protocols?\n \nBrian P. Jones\nSenior Software Engineer\n \n"},{"id":"186803","messageId":"CAJo=hJsshrJc0Onjph3LcQxEkXDSzEPp8TQetGoy9Rwz6OXRuw@mail.gmail.com","threadId":"29929","inReplyTo":"B1ECBDB2E23847488F70D870CBE563F70198D579@nawespscez06v.nadsuswe.nads.navy.mil","subject":"Re: CAC enabled authentication with git transfer protocols","fromName":"Shawn Pearce","fromEmail":"spearce@spearce.org","sentAt":"2012-03-13T01:53:31Z","receivedAt":"2012-03-13T01:53:31Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"On Mon, Mar 12, 2012 at 17:54, Jones, Brian P CTR\nSPAWARSYSCEN-PACIFIC, 63600 <brian.p.jones4.ctr@navy.mil> wrote:\n> Does anyone know if git is being used in a military CAC enabled environment? This means that the DoD CAC card is required to authenticate when hitting the git transfer protocol. This is a requirement before I can propose using git. I understand that git is able to use https as well as ssh or over port 9418. Is there any documentation on setting up CAC enabled git protocols?\n\nThe git:// protocol on port 9418 has no authentication. It won't meet\nyour requirements.\n\n\nFor Git over ssh://, Git just relies on the SSH client and server\nbinaries installed on the system. You would have to find out if these\nbinaries meet your requirements. If they do, you may just be able to\nuse SSH.\n\n\nGit 1.7.9 and later on https:// can use a credential helper binary to\nobtain the user's \"password\" string. A credential helper is an\nexternal program Git calls to help it authenticate over HTTP using\neither HTTP basic or HTTP digest authentication. It may be possible to\nwrite a git-credential-dodcac binary that does the magic required.\nInstall this binary in the user's $PATH, have them enable it with a\n`git config --global credential.helper dodcac` configuration setting,\nand away they go.\n\nIf a DoD CAC is like a one time password scheme, it may be possible to\nhave the user's \"password\" over HTTP actually be $password:$onetimepad\nor some such format, and then use a custom authentication system on\nthe server to decode this string and verify it.\n\nInternally at $DAYJOB we use a custom git-credential-$DAYJOB binary to\nacquire a unique token that identifies the caller and pass this to the\nserver over HTTPS. The HTTP server in turn verifies this string with\nthe authentication system. Its not really their password, its just a\nmutually agreed upon blob that was passed around between the client\nworkstation and the server.\n"},{"id":"186806","messageId":"CAOVFbFhbuWDFYcOqW3vcN==eC8495xuGRONLOrcWO6uZwJ2ETA@mail.gmail.com","threadId":"29929","inReplyTo":"CAJo=hJsshrJc0Onjph3LcQxEkXDSzEPp8TQetGoy9Rwz6OXRuw@mail.gmail.com","subject":"Re: CAC enabled authentication with git transfer protocols","fromName":"Chris Kees","fromEmail":"cekees@gmail.com","sentAt":"2012-03-13T02:20:39Z","receivedAt":"2012-03-13T02:20:39Z","isPatch":false,"sender":{"key":"cekees@gmail.com","avatar":"https://gravatar.com/avatar/e641423366bea929f162ec7953487481490d7e716b9489061f0744585fd122f3?d=mp&s=160"},"body":"On Mon, Mar 12, 2012 at 8:53 PM, Shawn Pearce <spearce@spearce.org> wrote:\n> On Mon, Mar 12, 2012 at 17:54, Jones, Brian P CTR\n> SPAWARSYSCEN-PACIFIC, 63600 <brian.p.jones4.ctr@navy.mil> wrote:\n>> Does anyone know if git is being used in a military CAC enabled environment? This means that the DoD CAC card is required to authenticate when hitting the git transfer protocol. This is a requirement before I can propose using git. I understand that git is able to use https as well as ssh or over port 9418. Is there any documentation on setting up CAC enabled git protocols?\n>\n> The git:// protocol on port 9418 has no authentication. It won't meet\n> your requirements.\n>\n>\n> For Git over ssh://, Git just relies on the SSH client and server\n> binaries installed on the system. You would have to find out if these\n> binaries meet your requirements. If they do, you may just be able to\n> use SSH.\n>\n\nIt seems like ssh might be the best shot. Kerberised ssh servers and\nclients can already be set up so that they use a CaC for\nauthentication.\n\n>\n> Git 1.7.9 and later on https:// can use a credential helper binary to\n> obtain the user's \"password\" string. A credential helper is an\n> external program Git calls to help it authenticate over HTTP using\n> either HTTP basic or HTTP digest authentication. It may be possible to\n> write a git-credential-dodcac binary that does the magic required.\n> Install this binary in the user's $PATH, have them enable it with a\n> `git config --global credential.helper dodcac` configuration setting,\n> and away they go.\n>\n> If a DoD CAC is like a one time password scheme, it may be possible to\n> have the user's \"password\" over HTTP actually be $password:$onetimepad\n> or some such format, and then use a custom authentication system on\n> the server to decode this string and verify it.\n>\n> Internally at $DAYJOB we use a custom git-credential-$DAYJOB binary to\n> acquire a unique token that identifies the caller and pass this to the\n> server over HTTPS. The HTTP server in turn verifies this string with\n> the authentication system. Its not really their password, its just a\n> mutually agreed upon blob that was passed around between the client\n> workstation and the server.\n> --\n> To unsubscribe from this list: send the line \"unsubscribe git\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"}]}