{"thread":{"id":"32605","subject":"[PATCH] Support FTP-over-SSL/TLS for regular FTP","startedAt":"2013-01-12T13:59:52Z","lastAt":"2013-04-07T19:10:39Z","messageCount":5,"participants":["Modestas Vainius","Matt Kraai","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"206596","messageId":"1357999192-877-1-git-send-email-modestas@vainius.eu","threadId":"32605","inReplyTo":null,"subject":"[PATCH] Support FTP-over-SSL/TLS for regular FTP","fromName":"Modestas Vainius","fromEmail":"modestas@vainius.eu","sentAt":"2013-01-12T13:59:52Z","receivedAt":"2013-01-12T13:59:52Z","isPatch":true,"sender":{"key":"modestas@vainius.eu","avatar":"https://avatars.githubusercontent.com/u/1032370?v=4"},"body":"Add a boolean http.sslTry option which allows to enable AUTH SSL/TLS and\nencrypted data transfers when connecting via regular FTP protocol.\n\nDefault is false since it might trigger certificate verification errors on\nmisconfigured servers.\n\nSigned-off-by: Modestas Vainius <modestas@vainius.eu>\n---\n Documentation/config.txt |    8 ++++++++\n http.c                   |   10 ++++++++++\n http.h                   |    9 +++++++++\n 3 files changed, 27 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex d5809e0..1abd161 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1406,6 +1406,14 @@ http.sslCAPath::\n \twith when fetching or pushing over HTTPS. Can be overridden\n \tby the 'GIT_SSL_CAPATH' environment variable.\n \n+http.sslTry::\n+\tAttempt to use AUTH SSL/TLS and encrypted data transfers\n+\twhen connecting via regular FTP protocol. This might be needed\n+\tif the FTP server requires it for security reasons or you wish\n+\tto connect securely whenever remote FTP server supports it.\n+\tDefault is false since it might trigger certificate verification\n+\terrors on misconfigured servers.\n+\n http.maxRequests::\n \tHow many HTTP requests to launch in parallel. Can be overridden\n \tby the 'GIT_HTTP_MAX_REQUESTS' environment variable. Default is 5.\ndiff --git a/http.c b/http.c\nindex 44f3525..d49a3d4 100644\n--- a/http.c\n+++ b/http.c\n@@ -30,6 +30,7 @@ static CURL *curl_default;\n char curl_errorstr[CURL_ERROR_SIZE];\n \n static int curl_ssl_verify = -1;\n+static int curl_ssl_try;\n static const char *ssl_cert;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n@@ -162,6 +163,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\t\tssl_cert_password_required = 1;\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.ssltry\", var)) {\n+\t\tcurl_ssl_try = git_config_bool(var, value);\n+\t\treturn 0;\n+\t}\n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n #ifndef USE_CURL_MULTI\n@@ -306,6 +311,11 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n+#ifdef CURLOPT_USE_SSL\n+    if (curl_ssl_try)\n+\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n+#endif\n+\n \tif (curl_http_proxy) {\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\ndiff --git a/http.h b/http.h\nindex 0a80d30..f861662 100644\n--- a/http.h\n+++ b/http.h\n@@ -42,6 +42,15 @@\n #define NO_CURL_IOCTL\n #endif\n \n+/*\n+ * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n+ * and the constants were known as CURLFTPSSL_*\n+*/\n+#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n+#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n+#define CURLUSESSL_TRY CURLFTPSSL_TRY\n+#endif\n+\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n1.7.10.4\n"},{"id":"206597","messageId":"20130112142521.GA21639@ftbfs.org","threadId":"32605","inReplyTo":"1357999192-877-1-git-send-email-modestas@vainius.eu","subject":"Re: [PATCH] Support FTP-over-SSL/TLS for regular FTP","fromName":"Matt Kraai","fromEmail":"kraai@ftbfs.org","sentAt":"2013-01-12T14:25:21Z","receivedAt":"2013-01-12T14:25:21Z","isPatch":true,"sender":{"key":"kraai@ftbfs.org","avatar":null},"body":"On Sat, Jan 12, 2013 at 03:59:52PM +0200, Modestas Vainius wrote:\n> @@ -306,6 +311,11 @@ static CURL *get_curl_handle(void)\n>  \tif (curl_ftp_no_epsv)\n>  \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n>  \n> +#ifdef CURLOPT_USE_SSL\n> +    if (curl_ssl_try)\n> +\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n> +#endif\n> +\n>  \tif (curl_http_proxy) {\n>  \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n>  \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n\nIt looks like the indentation of the \"if\" line you added is messed up.\n"},{"id":"206599","messageId":"7057807.F3QETssImX@mdxdesktop","threadId":"32605","inReplyTo":"20130112142521.GA21639@ftbfs.org","subject":"Re: [PATCH] Support FTP-over-SSL/TLS for regular FTP","fromName":"Modestas Vainius","fromEmail":"modestas@vainius.eu","sentAt":"2013-01-12T14:51:46Z","receivedAt":"2013-01-12T14:51:46Z","isPatch":true,"sender":{"key":"modestas@vainius.eu","avatar":"https://avatars.githubusercontent.com/u/1032370?v=4"},"body":"Hello,\n\nSaturday 12 January 2013 06:25:21 rašė:\n> On Sat, Jan 12, 2013 at 03:59:52PM +0200, Modestas Vainius wrote:\n> > @@ -306,6 +311,11 @@ static CURL *get_curl_handle(void)\n> > \n> >  \tif (curl_ftp_no_epsv)\n> >  \t\n> >  \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n> > \n> > +#ifdef CURLOPT_USE_SSL\n> > +    if (curl_ssl_try)\n> > +\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n> > +#endif\n> > +\n> > \n> >  \tif (curl_http_proxy) {\n> >  \t\n> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n> \n> It looks like the indentation of the \"if\" line you added is messed up.\n\nYeah, sorry about that. I will fix it.\n\n-- \nModestas Vainius <modestas@vainius.eu>\n"},{"id":"210227","messageId":"7vehg43nb5.fsf@alter.siamese.dyndns.org","threadId":"32605","inReplyTo":"7057807.F3QETssImX@mdxdesktop","subject":"Re: [PATCH] Support FTP-over-SSL/TLS for regular FTP","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2013-02-25T06:44:14Z","receivedAt":"2013-02-25T06:44:14Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Modestas Vainius <modestas@vainius.eu> writes:\n\n> Hello,\n>\n> Saturday 12 January 2013 06:25:21 rašė:\n>> On Sat, Jan 12, 2013 at 03:59:52PM +0200, Modestas Vainius wrote:\n>> > @@ -306,6 +311,11 @@ static CURL *get_curl_handle(void)\n>> > \n>> >  \tif (curl_ftp_no_epsv)\n>> >  \t\n>> >  \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n>> > \n>> > +#ifdef CURLOPT_USE_SSL\n>> > +    if (curl_ssl_try)\n>> > +\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n>> > +#endif\n>> > +\n>> > \n>> >  \tif (curl_http_proxy) {\n>> >  \t\n>> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n>> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n>> \n>> It looks like the indentation of the \"if\" line you added is messed up.\n>\n> Yeah, sorry about that. I will fix it.\n\nDid anything happen to this topic since then?\n"},{"id":"213465","messageId":"2136769.UdkVMxoiv9@mdxdesktop","threadId":"32605","inReplyTo":"7vehg43nb5.fsf@alter.siamese.dyndns.org","subject":"Re: [PATCH] Support FTP-over-SSL/TLS for regular FTP","fromName":"Modestas Vainius","fromEmail":"modestas@vainius.eu","sentAt":"2013-04-07T19:10:39Z","receivedAt":"2013-04-07T19:10:39Z","isPatch":true,"sender":{"key":"modestas@vainius.eu","avatar":"https://avatars.githubusercontent.com/u/1032370?v=4"},"body":"Hello,\n\nSunday 24 February 2013 22:44:14 rašė:\n> Modestas Vainius <modestas@vainius.eu> writes:\n> > Hello,\n> > \n> > Saturday 12 January 2013 06:25:21 rašė:\n> >> On Sat, Jan 12, 2013 at 03:59:52PM +0200, Modestas Vainius wrote:\n> >> > @@ -306,6 +311,11 @@ static CURL *get_curl_handle(void)\n> >> > \n> >> >  \tif (curl_ftp_no_epsv)\n> >> >  \t\n> >> >  \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n> >> > \n> >> > +#ifdef CURLOPT_USE_SSL\n> >> > +    if (curl_ssl_try)\n> >> > +\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n> >> > +#endif\n> >> > +\n> >> > \n> >> >  \tif (curl_http_proxy) {\n> >> >  \t\n> >> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n> >> >  \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\n> >> \n> >> It looks like the indentation of the \"if\" line you added is messed up.\n> > \n> > Yeah, sorry about that. I will fix it.\n> \n> Did anything happen to this topic since then?\n\nI'm very sorry about delay. Fixed patch is below.\n\nFrom 4f39352fe8dd85aa99f2141baa6a096da727c53e Mon Sep 17 00:00:00 2001\nFrom: Modestas Vainius <modestas@vainius.eu>\nDate: Sun, 7 Apr 2013 22:08:10 +0300\nSubject: [PATCH] Support FTP-over-SSL/TLS for regular FTP\n\nAdd a boolean http.sslTry option which allows to enable AUTH SSL/TLS and\nencrypted data transfers when connecting via regular FTP protocol.\n\nDefault is false since it might trigger certificate verification errors on\nmisconfigured servers.\n\nSigned-off-by: Modestas Vainius <modestas@vainius.eu>\n---\n Documentation/config.txt |    8 ++++++++\n http.c                   |   10 ++++++++++\n http.h                   |    9 +++++++++\n 3 files changed, 27 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex f79184c..da30cfd 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1447,6 +1447,14 @@ http.sslCAPath::\n \twith when fetching or pushing over HTTPS. Can be overridden\n \tby the 'GIT_SSL_CAPATH' environment variable.\n \n+http.sslTry::\n+\tAttempt to use AUTH SSL/TLS and encrypted data transfers\n+\twhen connecting via regular FTP protocol. This might be needed\n+\tif the FTP server requires it for security reasons or you wish\n+\tto connect securely whenever remote FTP server supports it.\n+\tDefault is false since it might trigger certificate verification\n+\terrors on misconfigured servers.\n+\n http.maxRequests::\n \tHow many HTTP requests to launch in parallel. Can be overridden\n \tby the 'GIT_HTTP_MAX_REQUESTS' environment variable. Default is 5.\ndiff --git a/http.c b/http.c\nindex 8803c70..f791fcb 100644\n--- a/http.c\n+++ b/http.c\n@@ -31,6 +31,7 @@ static CURL *curl_default;\n char curl_errorstr[CURL_ERROR_SIZE];\n \n static int curl_ssl_verify = -1;\n+static int curl_ssl_try;\n static const char *ssl_cert;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n@@ -163,6 +164,10 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\t\tssl_cert_password_required = 1;\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.ssltry\", var)) {\n+\t\tcurl_ssl_try = git_config_bool(var, value);\n+\t\treturn 0;\n+\t}\n \tif (!strcmp(\"http.minsessions\", var)) {\n \t\tmin_curl_sessions = git_config_int(var, value);\n #ifndef USE_CURL_MULTI\n@@ -307,6 +312,11 @@ static CURL *get_curl_handle(void)\n \tif (curl_ftp_no_epsv)\n \t\tcurl_easy_setopt(result, CURLOPT_FTP_USE_EPSV, 0);\n \n+#ifdef CURLOPT_USE_SSL\n+\tif (curl_ssl_try)\n+\t\tcurl_easy_setopt(result, CURLOPT_USE_SSL, CURLUSESSL_TRY);\n+#endif\n+\n \tif (curl_http_proxy) {\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY, curl_http_proxy);\n \t\tcurl_easy_setopt(result, CURLOPT_PROXYAUTH, CURLAUTH_ANY);\ndiff --git a/http.h b/http.h\nindex 25d1931..097514d 100644\n--- a/http.h\n+++ b/http.h\n@@ -42,6 +42,15 @@\n #define NO_CURL_IOCTL\n #endif\n \n+/*\n+ * CURLOPT_USE_SSL was known as CURLOPT_FTP_SSL up to 7.16.4,\n+ * and the constants were known as CURLFTPSSL_*\n+*/\n+#if !defined(CURLOPT_USE_SSL) && defined(CURLOPT_FTP_SSL)\n+#define CURLOPT_USE_SSL CURLOPT_FTP_SSL\n+#define CURLUSESSL_TRY CURLFTPSSL_TRY\n+#endif\n+\n struct slot_results {\n \tCURLcode curl_result;\n \tlong http_code;\n-- \n1.7.10.4\n\n\n\n-- \nModestas Vainius <modestas@vainius.eu>\n"}]}