{"thread":{"id":"52865","subject":"[PATCH 0/2] Add HTTPS proxy SSL options (cert, key, cainfo)","startedAt":"2020-02-21T21:36:51Z","lastAt":"2020-03-04T18:40:14Z","messageCount":15,"participants":["Jorge via GitGitGadget","Jorge Lopez Silva via GitGitGadget","Eric Sunshine","Jorge A López Silva","Junio C Hamano"],"isPatch":true,"patchVersion":1,"patchTotal":2},"messages":[{"id":"392278","messageId":"pull.559.git.1582321003.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":null,"subject":"[PATCH 0/2] Add HTTPS proxy SSL options (cert, key, cainfo)","fromName":"Jorge via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-21T21:36:41Z","receivedAt":"2020-02-21T21:36:51Z","isPatch":true,"sender":{"key":"griffin@gmx.es","avatar":null},"body":"Git currently supports connecting to proxies through HTTPS. However it does\nnot allow you to configure SSL options when connecting (i.e. client cert,\nkey, cainfo). These set of commits add the necessary options and\ndocumentation needed to support them.\n\nLibcurl already has support for this so changes are somewhat minimal.\n\nI didn't see integration tests under /t or tests that verified libcurl\nintegration. Is there another recommended way to add unit tests for these\nchanges? I did verify manually with an HTTPS proxy that the options were\nhaving the desired effect.\n\n./bin-wrappers/git -c http.proxy=https://<PROXY-HOSTNAME> \\\n-c http.proxycert=<CERT> -c http.proxykey=<KEY> \\\nclone https://github.com/jalopezsilva/dotfiles.git\n\nJorge Lopez Silva (2):\n  http: add client cert for HTTPS proxies.\n  config: documentation for HTTPS proxy client cert.\n\n Documentation/config/http.txt | 14 ++++++++++\n http.c                        | 48 ++++++++++++++++++++++++++++++++---\n 2 files changed, 59 insertions(+), 3 deletions(-)\n\n\nbase-commit: 51ebf55b9309824346a6589c9f3b130c6f371b8f\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-559%2Fjalopezsilva%2Fhttps_proxy_ssl_options-v1\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-559/jalopezsilva/https_proxy_ssl_options-v1\nPull-Request: https://github.com/gitgitgadget/git/pull/559\n-- \ngitgitgadget\n"},{"id":"392279","messageId":"3cf866d0384a0743e6625dd4e5124f00a5db5e7d.1582321003.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.git.1582321003.gitgitgadget@gmail.com","subject":"[PATCH 1/2] http: add client cert for HTTPS proxies.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-21T21:36:42Z","receivedAt":"2020-02-21T21:36:51Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nGit currently supports performing connections to HTTPS proxies but we\ndon't support doing mutual authentication with them (through TLS). This\ncommit adds the necessary options to be able to send a client\ncertificate to the HTTPS proxy.\n\nA client certificate can provide an alternative way of authentication\ninstead of using 'ProxyAuthorization' or other more common methods of\nauthentication.\n\nLibcurl supports this functionality already. The feature is guarded by\nthe first available libcurl version that supports these options.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n http.c | 48 +++++++++++++++++++++++++++++++++++++++++++++---\n 1 file changed, 45 insertions(+), 3 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 00a0e507633..141cf8f80cd 100644\n--- a/http.c\n+++ b/http.c\n@@ -86,6 +86,14 @@ static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv;\n static const char *curl_http_proxy;\n static const char *http_proxy_authmethod;\n+\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+static const char *http_proxy_ssl_cert;\n+static const char *http_proxy_ssl_key;\n+static const char *http_proxy_ssl_key_passwd;\n+#endif\n+static const char *http_proxy_ssl_ca_info;\n+\n static struct {\n \tconst char *name;\n \tlong curlauth_param;\n@@ -365,6 +373,20 @@ static int http_options(const char *var, const char *value, void *cb)\n \tif (!strcmp(\"http.proxyauthmethod\", var))\n \t\treturn git_config_string(&http_proxy_authmethod, var, value);\n \n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\tif (!strcmp(\"http.proxycert\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_cert, var, value);\n+\n+\tif (!strcmp(\"http.proxykey\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n+\n+\tif (!strcmp(\"http.proxykeypass\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_key_passwd, var, value);\n+\n+\tif (!strcmp(\"http.proxycainfo\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n+#endif\n+\n \tif (!strcmp(\"http.cookiefile\", var))\n \t\treturn git_config_pathname(&curl_cookie_file, var, value);\n \tif (!strcmp(\"http.savecookies\", var)) {\n@@ -924,8 +946,14 @@ static CURL *get_curl_handle(void)\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n-\t} else if (ssl_cainfo != NULL)\n-\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+\t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n+\t\tif (ssl_cainfo != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\t\tif (http_proxy_ssl_ca_info != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n+#endif\n+\t}\n \n \tif (curl_low_speed_limit > 0 && curl_low_speed_time > 0) {\n \t\tcurl_easy_setopt(result, CURLOPT_LOW_SPEED_LIMIT,\n@@ -1018,9 +1046,23 @@ static CURL *get_curl_handle(void)\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n #endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n-\t\telse if (starts_with(curl_http_proxy, \"https\"))\n+\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n \t\t\tcurl_easy_setopt(result,\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n+\n+\t\t\tif (http_proxy_ssl_cert != NULL) {\n+\t\t\t\tcurl_easy_setopt(result,\n+\t\t\t\t\tCURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n+\t\t\t\t}\n+\t\t\tif (http_proxy_ssl_key != NULL) {\n+\t\t\t\tcurl_easy_setopt(result,\n+\t\t\t\t\tCURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n+\t\t\t\t}\n+\t\t\tif (http_proxy_ssl_key_passwd != NULL) {\n+\t\t\t\tcurl_easy_setopt(result,\n+\t\t\t\t\tCURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_key_passwd);\n+\t\t\t\t}\n+\t\t\t}\n #endif\n \t\tif (strstr(curl_http_proxy, \"://\"))\n \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n-- \ngitgitgadget\n\n"},{"id":"392280","messageId":"583fdd0fe9b94c6031be40749d36ff61d55b55e3.1582321003.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.git.1582321003.gitgitgadget@gmail.com","subject":"[PATCH 2/2] config: documentation for HTTPS proxy client cert.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-21T21:36:43Z","receivedAt":"2020-02-21T21:36:53Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nThe commit adds 4 options, client cert, key, key password and CA info.\nThe CA info can be used to specify a different CA path to validate the\nHTTPS proxy cert.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n Documentation/config/http.txt | 14 ++++++++++++++\n 1 file changed, 14 insertions(+)\n\ndiff --git a/Documentation/config/http.txt b/Documentation/config/http.txt\nindex e806033aab8..7e704687e87 100644\n--- a/Documentation/config/http.txt\n+++ b/Documentation/config/http.txt\n@@ -29,6 +29,20 @@ http.proxyAuthMethod::\n * `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)\n --\n \n+http.proxycert::\n+\tFile indicating a client certificate to use to authenticate with an HTTPS proxy.\n+\n+http.proxykey::\n+\tFile indicating a private key to use to authenticate with an HTTPS proxy.\n+\n+http.proxykeypass::\n+\tWhen communicating to the proxy using TLS (using an HTTPS proxy), use this\n+\toption along `http.proxykey` to indicate a password for the key.\n+\n+http.proxycainfo::\n+\tFile containing the certificates to verify the proxy with when using an HTTPS\n+\tproxy.\n+\n http.emptyAuth::\n \tAttempt authentication without seeking a username or password.  This\n \tcan be used to attempt GSS-Negotiate authentication without specifying\n-- \ngitgitgadget\n"},{"id":"392284","messageId":"CAPig+cRYCC9MvAgVecEuvK1wqvWpVWS0ipmKPMKSctFbjHThvQ@mail.gmail.com","threadId":"52865","inReplyTo":"3cf866d0384a0743e6625dd4e5124f00a5db5e7d.1582321003.git.gitgitgadget@gmail.com","subject":"Re: [PATCH 1/2] http: add client cert for HTTPS proxies.","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2020-02-21T22:28:40Z","receivedAt":"2020-02-21T22:28:57Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Fri, Feb 21, 2020 at 4:37 PM Jorge Lopez Silva via GitGitGadget\n<gitgitgadget@gmail.com> wrote:\n> Git currently supports performing connections to HTTPS proxies but we\n> don't support doing mutual authentication with them (through TLS). This\n> commit adds the necessary options to be able to send a client\n> certificate to the HTTPS proxy.\n> [...]\n> Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n> ---\n> diff --git a/http.c b/http.c\n> @@ -1018,9 +1046,23 @@ static CURL *get_curl_handle(void)\n>  #if LIBCURL_VERSION_NUM >= 0x073400\n> -               else if (starts_with(curl_http_proxy, \"https\"))\n> +               else if (starts_with(curl_http_proxy, \"https\")) {\n>                         curl_easy_setopt(result,\n>                                 CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> +\n> +                       if (http_proxy_ssl_cert != NULL) {\n> +                               curl_easy_setopt(result,\n> +                                       CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n> +                               }\n> +                       if (http_proxy_ssl_key != NULL) {\n> +                               curl_easy_setopt(result,\n> +                                       CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n> +                               }\n> +                       if (http_proxy_ssl_key_passwd != NULL) {\n> +                               curl_easy_setopt(result,\n> +                                       CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_key_passwd);\n> +                               }\n> +                       }\n>  #endif\n\nAll the closing braces in this hunk seem to be over-indented. Also,\nall of the braces for the one-liner 'if' bodies can be dropped, thus\nmaking it less noisy.\n"},{"id":"392576","messageId":"CAJyLMU9yKZQ673PTopxVcyx-OAk2kVSAt8nYLYYQw9-GFF00ZQ@mail.gmail.com","threadId":"52865","inReplyTo":"CAPig+cRYCC9MvAgVecEuvK1wqvWpVWS0ipmKPMKSctFbjHThvQ@mail.gmail.com","subject":"Re: [PATCH 1/2] http: add client cert for HTTPS proxies.","fromName":"Jorge A López Silva","fromEmail":"jalopezsilva@gmail.com","sentAt":"2020-02-26T21:05:00Z","receivedAt":"2020-02-26T21:05:13Z","isPatch":true,"sender":{"key":"jalopezsilva@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1276443?v=4"},"body":"Thanks Eric for the feedback. I'm addressing your comments and sending a v2.\n\n\nOn Fri, Feb 21, 2020 at 2:28 PM Eric Sunshine <sunshine@sunshineco.com> wrote:\n>\n> On Fri, Feb 21, 2020 at 4:37 PM Jorge Lopez Silva via GitGitGadget\n> <gitgitgadget@gmail.com> wrote:\n> > Git currently supports performing connections to HTTPS proxies but we\n> > don't support doing mutual authentication with them (through TLS). This\n> > commit adds the necessary options to be able to send a client\n> > certificate to the HTTPS proxy.\n> > [...]\n> > Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n> > ---\n> > diff --git a/http.c b/http.c\n> > @@ -1018,9 +1046,23 @@ static CURL *get_curl_handle(void)\n> >  #if LIBCURL_VERSION_NUM >= 0x073400\n> > -               else if (starts_with(curl_http_proxy, \"https\"))\n> > +               else if (starts_with(curl_http_proxy, \"https\")) {\n> >                         curl_easy_setopt(result,\n> >                                 CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> > +\n> > +                       if (http_proxy_ssl_cert != NULL) {\n> > +                               curl_easy_setopt(result,\n> > +                                       CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n> > +                               }\n> > +                       if (http_proxy_ssl_key != NULL) {\n> > +                               curl_easy_setopt(result,\n> > +                                       CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n> > +                               }\n> > +                       if (http_proxy_ssl_key_passwd != NULL) {\n> > +                               curl_easy_setopt(result,\n> > +                                       CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_key_passwd);\n> > +                               }\n> > +                       }\n> >  #endif\n>\n> All the closing braces in this hunk seem to be over-indented. Also,\n> all of the braces for the one-liner 'if' bodies can be dropped, thus\n> making it less noisy.\n"},{"id":"392584","messageId":"pull.559.v2.git.1582759438.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.git.1582321003.gitgitgadget@gmail.com","subject":"[PATCH v2 0/2] Add HTTPS proxy SSL options (cert, key, cainfo)","fromName":"Jorge via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-26T23:23:56Z","receivedAt":"2020-02-26T23:24:03Z","isPatch":true,"sender":{"key":"griffin@gmx.es","avatar":null},"body":"Git currently supports connecting to proxies through HTTPS. However it does\nnot allow you to configure SSL options when connecting (i.e. client cert,\nkey, cainfo). These set of commits add the necessary options and\ndocumentation needed to support them.\n\nLibcurl already has support for this so changes are somewhat minimal.\n\nI ran the CI tests and verified manually with an HTTPS proxy that changes\nare working as expected. I didn't see integration tests under /t or tests\nthat verified libcurl integration. \n\n./bin-wrappers/git -c http.proxy=https://<PROXY-HOSTNAME> \\\n-c http.proxycert=<CERT> -c http.proxykey=<KEY> \\\nclone https://github.com/jalopezsilva/dotfiles.git\n\nJorge Lopez Silva (2):\n  http: add client cert for HTTPS proxies.\n  config: documentation for HTTPS proxy client cert.\n\n Documentation/config/http.txt | 14 ++++++++++\n http.c                        | 48 +++++++++++++++++++++++++++++++----\n 2 files changed, 57 insertions(+), 5 deletions(-)\n\n\nbase-commit: 51ebf55b9309824346a6589c9f3b130c6f371b8f\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-559%2Fjalopezsilva%2Fhttps_proxy_ssl_options-v2\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-559/jalopezsilva/https_proxy_ssl_options-v2\nPull-Request: https://github.com/gitgitgadget/git/pull/559\n\nRange-diff vs v1:\n\n 1:  3cf866d0384 ! 1:  a5d980e7501 http: add client cert for HTTPS proxies.\n     @@ -27,7 +27,7 @@\n      +#if LIBCURL_VERSION_NUM >= 0x073400\n      +static const char *http_proxy_ssl_cert;\n      +static const char *http_proxy_ssl_key;\n     -+static const char *http_proxy_ssl_key_passwd;\n     ++static const char *http_proxy_ssl_keypasswd;\n      +#endif\n      +static const char *http_proxy_ssl_ca_info;\n      +\n     @@ -46,7 +46,7 @@\n      +\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n      +\n      +\tif (!strcmp(\"http.proxykeypass\", var))\n     -+\t\treturn git_config_string(&http_proxy_ssl_key_passwd, var, value);\n     ++\t\treturn git_config_string(&http_proxy_ssl_keypasswd, var, value);\n      +\n      +\tif (!strcmp(\"http.proxycainfo\", var))\n      +\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n     @@ -77,23 +77,21 @@\n       #endif\n       #if LIBCURL_VERSION_NUM >= 0x073400\n      -\t\telse if (starts_with(curl_http_proxy, \"https\"))\n     +-\t\t\tcurl_easy_setopt(result,\n     +-\t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n      +\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n     - \t\t\tcurl_easy_setopt(result,\n     - \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n     ++\t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n      +\n     -+\t\t\tif (http_proxy_ssl_cert != NULL) {\n     -+\t\t\t\tcurl_easy_setopt(result,\n     -+\t\t\t\t\tCURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n     -+\t\t\t\t}\n     -+\t\t\tif (http_proxy_ssl_key != NULL) {\n     -+\t\t\t\tcurl_easy_setopt(result,\n     -+\t\t\t\t\tCURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n     -+\t\t\t\t}\n     -+\t\t\tif (http_proxy_ssl_key_passwd != NULL) {\n     -+\t\t\t\tcurl_easy_setopt(result,\n     -+\t\t\t\t\tCURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_key_passwd);\n     -+\t\t\t\t}\n     -+\t\t\t}\n     ++\t\t\tif (http_proxy_ssl_cert != NULL)\n     ++\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n     ++\n     ++\t\t\tif (http_proxy_ssl_key != NULL)\n     ++\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n     ++\n     ++\t\t\tif (http_proxy_ssl_keypasswd != NULL)\n     ++\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);\n     ++\n     ++\t\t}\n       #endif\n       \t\tif (strstr(curl_http_proxy, \"://\"))\n       \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n 2:  583fdd0fe9b = 2:  c40207a3928 config: documentation for HTTPS proxy client cert.\n\n-- \ngitgitgadget\n"},{"id":"392585","messageId":"c40207a3928f9cbc490b9ef2e99e7cba7788e7c0.1582759438.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.v2.git.1582759438.gitgitgadget@gmail.com","subject":"[PATCH v2 2/2] config: documentation for HTTPS proxy client cert.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-26T23:23:58Z","receivedAt":"2020-02-26T23:24:04Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nThe commit adds 4 options, client cert, key, key password and CA info.\nThe CA info can be used to specify a different CA path to validate the\nHTTPS proxy cert.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n Documentation/config/http.txt | 14 ++++++++++++++\n 1 file changed, 14 insertions(+)\n\ndiff --git a/Documentation/config/http.txt b/Documentation/config/http.txt\nindex e806033aab8..7e704687e87 100644\n--- a/Documentation/config/http.txt\n+++ b/Documentation/config/http.txt\n@@ -29,6 +29,20 @@ http.proxyAuthMethod::\n * `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)\n --\n \n+http.proxycert::\n+\tFile indicating a client certificate to use to authenticate with an HTTPS proxy.\n+\n+http.proxykey::\n+\tFile indicating a private key to use to authenticate with an HTTPS proxy.\n+\n+http.proxykeypass::\n+\tWhen communicating to the proxy using TLS (using an HTTPS proxy), use this\n+\toption along `http.proxykey` to indicate a password for the key.\n+\n+http.proxycainfo::\n+\tFile containing the certificates to verify the proxy with when using an HTTPS\n+\tproxy.\n+\n http.emptyAuth::\n \tAttempt authentication without seeking a username or password.  This\n \tcan be used to attempt GSS-Negotiate authentication without specifying\n-- \ngitgitgadget\n"},{"id":"392586","messageId":"a5d980e7501b1e0ab6f20a97136cd3a58427a139.1582759438.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.v2.git.1582759438.gitgitgadget@gmail.com","subject":"[PATCH v2 1/2] http: add client cert for HTTPS proxies.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-02-26T23:23:57Z","receivedAt":"2020-02-26T23:24:04Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nGit currently supports performing connections to HTTPS proxies but we\ndon't support doing mutual authentication with them (through TLS). This\ncommit adds the necessary options to be able to send a client\ncertificate to the HTTPS proxy.\n\nA client certificate can provide an alternative way of authentication\ninstead of using 'ProxyAuthorization' or other more common methods of\nauthentication.\n\nLibcurl supports this functionality already. The feature is guarded by\nthe first available libcurl version that supports these options.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n http.c | 48 +++++++++++++++++++++++++++++++++++++++++++-----\n 1 file changed, 43 insertions(+), 5 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 00a0e507633..88782d39f15 100644\n--- a/http.c\n+++ b/http.c\n@@ -86,6 +86,14 @@ static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv;\n static const char *curl_http_proxy;\n static const char *http_proxy_authmethod;\n+\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+static const char *http_proxy_ssl_cert;\n+static const char *http_proxy_ssl_key;\n+static const char *http_proxy_ssl_keypasswd;\n+#endif\n+static const char *http_proxy_ssl_ca_info;\n+\n static struct {\n \tconst char *name;\n \tlong curlauth_param;\n@@ -365,6 +373,20 @@ static int http_options(const char *var, const char *value, void *cb)\n \tif (!strcmp(\"http.proxyauthmethod\", var))\n \t\treturn git_config_string(&http_proxy_authmethod, var, value);\n \n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\tif (!strcmp(\"http.proxycert\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_cert, var, value);\n+\n+\tif (!strcmp(\"http.proxykey\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n+\n+\tif (!strcmp(\"http.proxykeypass\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_keypasswd, var, value);\n+\n+\tif (!strcmp(\"http.proxycainfo\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n+#endif\n+\n \tif (!strcmp(\"http.cookiefile\", var))\n \t\treturn git_config_pathname(&curl_cookie_file, var, value);\n \tif (!strcmp(\"http.savecookies\", var)) {\n@@ -924,8 +946,14 @@ static CURL *get_curl_handle(void)\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n-\t} else if (ssl_cainfo != NULL)\n-\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+\t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n+\t\tif (ssl_cainfo != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\t\tif (http_proxy_ssl_ca_info != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n+#endif\n+\t}\n \n \tif (curl_low_speed_limit > 0 && curl_low_speed_time > 0) {\n \t\tcurl_easy_setopt(result, CURLOPT_LOW_SPEED_LIMIT,\n@@ -1018,9 +1046,19 @@ static CURL *get_curl_handle(void)\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n #endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n-\t\telse if (starts_with(curl_http_proxy, \"https\"))\n-\t\t\tcurl_easy_setopt(result,\n-\t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n+\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n+\t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n+\n+\t\t\tif (http_proxy_ssl_cert != NULL)\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n+\n+\t\t\tif (http_proxy_ssl_key != NULL)\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n+\n+\t\t\tif (http_proxy_ssl_keypasswd != NULL)\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);\n+\n+\t\t}\n #endif\n \t\tif (strstr(curl_http_proxy, \"://\"))\n \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n-- \ngitgitgadget\n\n"},{"id":"392634","messageId":"xmqqftevg9uz.fsf@gitster-ct.c.googlers.com","threadId":"52865","inReplyTo":"a5d980e7501b1e0ab6f20a97136cd3a58427a139.1582759438.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 1/2] http: add client cert for HTTPS proxies.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2020-02-27T18:31:48Z","receivedAt":"2020-02-27T18:31:59Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Jorge Lopez Silva via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> +#if LIBCURL_VERSION_NUM >= 0x073400\n> +static const char *http_proxy_ssl_cert;\n> +static const char *http_proxy_ssl_key;\n> +static const char *http_proxy_ssl_keypasswd;\n> +#endif\n> +static const char *http_proxy_ssl_ca_info;\n> +\n>  static struct {\n>  \tconst char *name;\n>  \tlong curlauth_param;\n> @@ -365,6 +373,20 @@ static int http_options(const char *var, const char *value, void *cb)\n>  \tif (!strcmp(\"http.proxyauthmethod\", var))\n>  \t\treturn git_config_string(&http_proxy_authmethod, var, value);\n>  \n> +#if LIBCURL_VERSION_NUM >= 0x073400\n> +\tif (!strcmp(\"http.proxycert\", var))\n> +\t\treturn git_config_string(&http_proxy_ssl_cert, var, value);\n> +\n> +\tif (!strcmp(\"http.proxykey\", var))\n> +\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n> +\n> +\tif (!strcmp(\"http.proxykeypass\", var))\n> +\t\treturn git_config_string(&http_proxy_ssl_keypasswd, var, value);\n> +\n> +\tif (!strcmp(\"http.proxycainfo\", var))\n> +\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n> +#endif\n\nYou may copy around your ~/.gitconfig to multiple hosts, some may\nhave newer and others may have older versions of libcurl, so it\nwould be OK for a version of Git built with older libcurl to at\nleast see and parse configurations meant for newer one, if only\nto ignore and discard.\n\nThe only two effects these #if/#endif have are (1) they save a tiny\nbit of memory, code and runtime cycle on an older platform and (2)\nthey make the resuting code ugly and harder to read.  I do not think\nthat the tradeoff is worth it.\n\n>  \tif (!strcmp(\"http.cookiefile\", var))\n>  \t\treturn git_config_pathname(&curl_cookie_file, var, value);\n>  \tif (!strcmp(\"http.savecookies\", var)) {\n> @@ -924,8 +946,14 @@ static CURL *get_curl_handle(void)\n>  #if LIBCURL_VERSION_NUM >= 0x073400\n>  \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n>  #endif\n> -\t} else if (ssl_cainfo != NULL)\n> -\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n> +\t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n> +\t\tif (ssl_cainfo != NULL)\n> +\t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n> +#if LIBCURL_VERSION_NUM >= 0x073400\n> +\t\tif (http_proxy_ssl_ca_info != NULL)\n> +\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n> +#endif\n> +\t}\n\nOn this codepath, unlike the config and variable definitions,\n#if/#endif is absolutely necessary.\n\nIn any case, the code around here is messy, but it is mostly due to\nthe fact that the existing #if/#endif with if/elseif/... cascade was\nmessy.  The general idea is\n\n * We want to honor ssl_cainfo and http_proxy_ssl_ca_info, and use\n   CAINFO when set, but\n\n * When http_schannel_use_ssl_cainfo is not in effect and\n   http_ssl_backend is schannel, ssl_cainfo/http_proxy_ssl_ca_info\n   business is completely skipped, and these two CAINFO are cleared\n   instead.\n\nI do not know if the above is the best code structure to express\nthat, but at least the way this patch adds code is the least noisy,\nI guess.\n\n> @@ -1018,9 +1046,19 @@ static CURL *get_curl_handle(void)\n>  \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n>  #endif\n>  #if LIBCURL_VERSION_NUM >= 0x073400\n> -\t\telse if (starts_with(curl_http_proxy, \"https\"))\n> -\t\t\tcurl_easy_setopt(result,\n> -\t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> +\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n> +\t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> +\n> +\t\t\tif (http_proxy_ssl_cert != NULL)\n> +\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n> +\n> +\t\t\tif (http_proxy_ssl_key != NULL)\n> +\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n> +\n> +\t\t\tif (http_proxy_ssl_keypasswd != NULL)\n> +\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);\n\nThis part is more or less straight-forward.\n\nThis is a minor tangent, but I see many \"var != NULL\" instances used\nas the condition to if statements, which we tend to frown upon\n(instead just say \"if (var) ...\").  I know there are already many in\nthe existing code in this file, but this patch is making it even\nworse.\n\n> +\t\t}\n>  #endif\n>  \t\tif (strstr(curl_http_proxy, \"://\"))\n>  \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n"},{"id":"392635","messageId":"xmqqblpjg8mf.fsf@gitster-ct.c.googlers.com","threadId":"52865","inReplyTo":"c40207a3928f9cbc490b9ef2e99e7cba7788e7c0.1582759438.git.gitgitgadget@gmail.com","subject":"Re: [PATCH v2 2/2] config: documentation for HTTPS proxy client cert.","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2020-02-27T18:58:32Z","receivedAt":"2020-02-27T18:58:40Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"Jorge Lopez Silva via GitGitGadget\" <gitgitgadget@gmail.com>\nwrites:\n\n> From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n>\n> The commit adds 4 options, client cert, key, key password and CA info.\n> The CA info can be used to specify a different CA path to validate the\n> HTTPS proxy cert.\n>\n> Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n> ---\n\nThanks, this should be part of the previous patch, as it was that\ncommit, not this one, that adds 4 options ;-)\n\n> +http.proxycert::\n> +\tFile indicating a client certificate to use to authenticate with an HTTPS proxy.\n> +\n> +http.proxykey::\n> +\tFile indicating a private key to use to authenticate with an HTTPS proxy.\n\nI think these files not merely \"indicate\" but they themselves\n\"hold\", \"contain\" and/or \"store\" the certificate and key.  Perhaps\nmore like...\n\n\tThe pathname of a file that stores a client certificate to ...\n\nAlso, it is customary to camelCase the configuration variable names.\nAs I understand http.proxykey is roughly corresponds to existing\nhttp.sslKey (the former is for proxy, the latter is for the target\nhost), I'd expect these two to be spelled http.proxySSLCert and\nhttp.proxySSLKey respectively (without omitting \"SSL\", as that is\nthe underlying cURL option name if I am reading the code in 1/2\ncorrectly).\n\n> +http.proxykeypass::\n> +\tWhen communicating to the proxy using TLS (using an HTTPS proxy), use this\n> +\toption along `http.proxykey` to indicate a password for the key.\n\nAnd this would be \"http.proxyKeyPasswd\" for the same two reasons.\n\nThere are a couple of curious things, though:\n\n * Is it a good idea to use a keyfile that is encrypted, but leave\n   the encryption password on disk in the configuration file to\n   begin with?\n\n * This teaches our system about PROXY_KEYPASSWD that protects\n   PROXY_SSLKEY, but why isn't there a similar configuration\n   variable for CURLOPT_KEYPASSWD that protects CURLOPT_SSLKEY?\n\nIt is possible that the answer to these questions are the same---an\non-disk password is a bad idea, so we deliberately omit a config\nthat gives value to CURLOPT_KEYPASSWD and instead use the credential\nsubsystem (see http.c::has_cert_password() and its caller).  If so,\nI think it would be prudent to follow the same pattern if possible?\n\n> +http.proxycainfo::\n> +\tFile containing the certificates to verify the proxy with when using an HTTPS\n> +\tproxy.\n> +\n>  http.emptyAuth::\n>  \tAttempt authentication without seeking a username or password.  This\n>  \tcan be used to attempt GSS-Negotiate authentication without specifying\n"},{"id":"392768","messageId":"CAJyLMU99__oKfNufVQQP+zodPVJV0bhFbyQzbrjfF11+UKVOCA@mail.gmail.com","threadId":"52865","inReplyTo":"xmqqftevg9uz.fsf@gitster-ct.c.googlers.com","subject":"Re: [PATCH v2 1/2] http: add client cert for HTTPS proxies.","fromName":"Jorge A López Silva","fromEmail":"jalopezsilva@gmail.com","sentAt":"2020-03-03T01:41:29Z","receivedAt":"2020-03-03T01:41:44Z","isPatch":true,"sender":{"key":"jalopezsilva@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1276443?v=4"},"body":"> You may copy around your ~/.gitconfig to multiple hosts, some may\n> have newer and others may have older versions of libcurl, so it\n> would be OK for a version of Git built with older libcurl to at\n> least see and parse configurations meant for newer one, if only\n> to ignore and discard.\n> The only two effects these #if/#endif have are (1) they save a tiny\n> bit of memory, code and runtime cycle on an older platform and (2)\n> they make the resuting code ugly and harder to read.  I do not think\n> that the tradeoff is worth it.\n\nI agree, thanks for the input. I'll remove the #if/#endif from the variables.\n\n>  This part is more or less straight-forward.\n> This is a minor tangent, but I see many \"var != NULL\" instances used\n> as the condition to if statements, which we tend to frown upon\n> (instead just say \"if (var) ...\").  I know there are already many in\n> the existing code in this file, but this patch is making it even\n> worse.\n\nUnderstood, will fix!\n\n\nOn Thu, Feb 27, 2020 at 10:31 AM Junio C Hamano <gitster@pobox.com> wrote:\n>\n> \"Jorge Lopez Silva via GitGitGadget\" <gitgitgadget@gmail.com>\n> writes:\n>\n> > +#if LIBCURL_VERSION_NUM >= 0x073400\n> > +static const char *http_proxy_ssl_cert;\n> > +static const char *http_proxy_ssl_key;\n> > +static const char *http_proxy_ssl_keypasswd;\n> > +#endif\n> > +static const char *http_proxy_ssl_ca_info;\n> > +\n> >  static struct {\n> >       const char *name;\n> >       long curlauth_param;\n> > @@ -365,6 +373,20 @@ static int http_options(const char *var, const char *value, void *cb)\n> >       if (!strcmp(\"http.proxyauthmethod\", var))\n> >               return git_config_string(&http_proxy_authmethod, var, value);\n> >\n> > +#if LIBCURL_VERSION_NUM >= 0x073400\n> > +     if (!strcmp(\"http.proxycert\", var))\n> > +             return git_config_string(&http_proxy_ssl_cert, var, value);\n> > +\n> > +     if (!strcmp(\"http.proxykey\", var))\n> > +             return git_config_string(&http_proxy_ssl_key, var, value);\n> > +\n> > +     if (!strcmp(\"http.proxykeypass\", var))\n> > +             return git_config_string(&http_proxy_ssl_keypasswd, var, value);\n> > +\n> > +     if (!strcmp(\"http.proxycainfo\", var))\n> > +             return git_config_string(&http_proxy_ssl_ca_info, var, value);\n> > +#endif\n>\n> You may copy around your ~/.gitconfig to multiple hosts, some may\n> have newer and others may have older versions of libcurl, so it\n> would be OK for a version of Git built with older libcurl to at\n> least see and parse configurations meant for newer one, if only\n> to ignore and discard.\n>\n> The only two effects these #if/#endif have are (1) they save a tiny\n> bit of memory, code and runtime cycle on an older platform and (2)\n> they make the resuting code ugly and harder to read.  I do not think\n> that the tradeoff is worth it.\n>\n> >       if (!strcmp(\"http.cookiefile\", var))\n> >               return git_config_pathname(&curl_cookie_file, var, value);\n> >       if (!strcmp(\"http.savecookies\", var)) {\n> > @@ -924,8 +946,14 @@ static CURL *get_curl_handle(void)\n> >  #if LIBCURL_VERSION_NUM >= 0x073400\n> >               curl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n> >  #endif\n> > -     } else if (ssl_cainfo != NULL)\n> > -             curl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n> > +     } else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n> > +             if (ssl_cainfo != NULL)\n> > +                     curl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n> > +#if LIBCURL_VERSION_NUM >= 0x073400\n> > +             if (http_proxy_ssl_ca_info != NULL)\n> > +                     curl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n> > +#endif\n> > +     }\n>\n> On this codepath, unlike the config and variable definitions,\n> #if/#endif is absolutely necessary.\n>\n> In any case, the code around here is messy, but it is mostly due to\n> the fact that the existing #if/#endif with if/elseif/... cascade was\n> messy.  The general idea is\n>\n>  * We want to honor ssl_cainfo and http_proxy_ssl_ca_info, and use\n>    CAINFO when set, but\n>\n>  * When http_schannel_use_ssl_cainfo is not in effect and\n>    http_ssl_backend is schannel, ssl_cainfo/http_proxy_ssl_ca_info\n>    business is completely skipped, and these two CAINFO are cleared\n>    instead.\n>\n> I do not know if the above is the best code structure to express\n> that, but at least the way this patch adds code is the least noisy,\n> I guess.\n>\n> > @@ -1018,9 +1046,19 @@ static CURL *get_curl_handle(void)\n> >                               CURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n> >  #endif\n> >  #if LIBCURL_VERSION_NUM >= 0x073400\n> > -             else if (starts_with(curl_http_proxy, \"https\"))\n> > -                     curl_easy_setopt(result,\n> > -                             CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> > +             else if (starts_with(curl_http_proxy, \"https\")) {\n> > +                     curl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n> > +\n> > +                     if (http_proxy_ssl_cert != NULL)\n> > +                             curl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n> > +\n> > +                     if (http_proxy_ssl_key != NULL)\n> > +                             curl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n> > +\n> > +                     if (http_proxy_ssl_keypasswd != NULL)\n> > +                             curl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);\n>\n> This part is more or less straight-forward.\n>\n> This is a minor tangent, but I see many \"var != NULL\" instances used\n> as the condition to if statements, which we tend to frown upon\n> (instead just say \"if (var) ...\").  I know there are already many in\n> the existing code in this file, but this patch is making it even\n> worse.\n>\n> > +             }\n> >  #endif\n> >               if (strstr(curl_http_proxy, \"://\"))\n> >                       credential_from_url(&proxy_auth, curl_http_proxy);\n"},{"id":"392769","messageId":"CAJyLMU8-OUvOoP1hvgu4PC8iO7oynrvo2CW94HL-neu4RcZ=Ew@mail.gmail.com","threadId":"52865","inReplyTo":"xmqqblpjg8mf.fsf@gitster-ct.c.googlers.com","subject":"Re: [PATCH v2 2/2] config: documentation for HTTPS proxy client cert.","fromName":"Jorge A López Silva","fromEmail":"jalopezsilva@gmail.com","sentAt":"2020-03-03T01:47:19Z","receivedAt":"2020-03-03T01:47:34Z","isPatch":true,"sender":{"key":"jalopezsilva@gmail.com","avatar":"https://avatars.githubusercontent.com/u/1276443?v=4"},"body":"> Thanks, this should be part of the previous patch, as it was that\n> commit, not this one, that adds 4 options ;-)\n\nHaha, yeah, you're right. I'll collapse the commits into a single one.\n\n>  I think these files not merely \"indicate\" but they themselves\n> \"hold\", \"contain\" and/or \"store\" the certificate and key.  Perhaps\n> more like...\n>         The pathname of a file that stores a client certificate to ...\n> Also, it is customary to camelCase the configuration variable names.\n> As I understand http.proxykey is roughly corresponds to existing\n> http.sslKey (the former is for proxy, the latter is for the target\n> host), I'd expect these two to be spelled http.proxySSLCert and\n> http.proxySSLKey respectively (without omitting \"SSL\", as that is\n> the underlying cURL option name if I am reading the code in 1/2\n> correctly).\n\nGood point. Better descriptions and names will be added.\n\n> It is possible that the answer to these questions are the same---an\n> on-disk password is a bad idea, so we deliberately omit a config\n> that gives value to CURLOPT_KEYPASSWD and instead use the credential\n> subsystem (see http.c::has_cert_password() and its caller).  If so,\n> I think it would be prudent to follow the same pattern if possible?\n\n\nExcellent point. Will adjust to re-use the same pattern.\n\n\nOn Thu, Feb 27, 2020 at 10:58 AM Junio C Hamano <gitster@pobox.com> wrote:\n>\n> \"Jorge Lopez Silva via GitGitGadget\" <gitgitgadget@gmail.com>\n> writes:\n>\n> > From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n> >\n> > The commit adds 4 options, client cert, key, key password and CA info.\n> > The CA info can be used to specify a different CA path to validate the\n> > HTTPS proxy cert.\n> >\n> > Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n> > ---\n>\n> Thanks, this should be part of the previous patch, as it was that\n> commit, not this one, that adds 4 options ;-)\n>\n> > +http.proxycert::\n> > +     File indicating a client certificate to use to authenticate with an HTTPS proxy.\n> > +\n> > +http.proxykey::\n> > +     File indicating a private key to use to authenticate with an HTTPS proxy.\n>\n> I think these files not merely \"indicate\" but they themselves\n> \"hold\", \"contain\" and/or \"store\" the certificate and key.  Perhaps\n> more like...\n>\n>         The pathname of a file that stores a client certificate to ...\n>\n> Also, it is customary to camelCase the configuration variable names.\n> As I understand http.proxykey is roughly corresponds to existing\n> http.sslKey (the former is for proxy, the latter is for the target\n> host), I'd expect these two to be spelled http.proxySSLCert and\n> http.proxySSLKey respectively (without omitting \"SSL\", as that is\n> the underlying cURL option name if I am reading the code in 1/2\n> correctly).\n>\n> > +http.proxykeypass::\n> > +     When communicating to the proxy using TLS (using an HTTPS proxy), use this\n> > +     option along `http.proxykey` to indicate a password for the key.\n>\n> And this would be \"http.proxyKeyPasswd\" for the same two reasons.\n>\n> There are a couple of curious things, though:\n>\n>  * Is it a good idea to use a keyfile that is encrypted, but leave\n>    the encryption password on disk in the configuration file to\n>    begin with?\n>\n>  * This teaches our system about PROXY_KEYPASSWD that protects\n>    PROXY_SSLKEY, but why isn't there a similar configuration\n>    variable for CURLOPT_KEYPASSWD that protects CURLOPT_SSLKEY?\n>\n> It is possible that the answer to these questions are the same---an\n> on-disk password is a bad idea, so we deliberately omit a config\n> that gives value to CURLOPT_KEYPASSWD and instead use the credential\n> subsystem (see http.c::has_cert_password() and its caller).  If so,\n> I think it would be prudent to follow the same pattern if possible?\n>\n> > +http.proxycainfo::\n> > +     File containing the certificates to verify the proxy with when using an HTTPS\n> > +     proxy.\n> > +\n> >  http.emptyAuth::\n> >       Attempt authentication without seeking a username or password.  This\n> >       can be used to attempt GSS-Negotiate authentication without specifying\n"},{"id":"392868","messageId":"e18b342819b445281732269def1912a044171bab.1583347206.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.v3.git.1583347206.gitgitgadget@gmail.com","subject":"[PATCH v3 1/2] http: add client cert for HTTPS proxies.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-03-04T18:40:05Z","receivedAt":"2020-03-04T18:40:13Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nGit currently supports performing connections to HTTPS proxies but we\ndon't support doing mutual authentication with them (through TLS). This\ncommit adds the necessary options to be able to send a client\ncertificate to the HTTPS proxy.\n\nA client certificate can provide an alternative way of authentication\ninstead of using 'ProxyAuthorization' or other more common methods of\nauthentication.  Libcurl supports this functionality already so changes\nare somewhat minimal. The feature is guarded by the first available\nlibcurl version that supports these options.\n\n4 configuration options are added and documented, cert, key, cert\npassword protected and CA info. The CA info should be used to specify a\ndifferent CA path to validate the HTTPS proxy cert.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n Documentation/config/http.txt | 17 +++++++++\n http.c                        | 67 ++++++++++++++++++++++++++++++++---\n 2 files changed, 79 insertions(+), 5 deletions(-)\n\ndiff --git a/Documentation/config/http.txt b/Documentation/config/http.txt\nindex e806033aab8..7d398f9afba 100644\n--- a/Documentation/config/http.txt\n+++ b/Documentation/config/http.txt\n@@ -29,6 +29,23 @@ http.proxyAuthMethod::\n * `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)\n --\n \n+http.proxySSLCert::\n+\tThe pathname of a file that stores a client certificate to use to authenticate\n+\twith an HTTPS proxy.\n+\n+http.proxySSLKey::\n+\tThe pathname of a file that stores a private key to use to authenticate with\n+\tan HTTPS proxy.\n+\n+http.proxySSLCertPasswordProtected::\n+\tEnable Git's password prompt for the proxy SSL certificate.  Otherwise OpenSSL\n+\twill prompt the user, possibly many times, if the certificate or private key\n+\tis encrypted.\n+\n+http.proxySSLCAInfo::\n+\tPathname to the file containing the certificate bundle that should be used to\n+\tverify the proxy with when using an HTTPS proxy.\n+\n http.emptyAuth::\n \tAttempt authentication without seeking a username or password.  This\n \tcan be used to attempt GSS-Negotiate authentication without specifying\ndiff --git a/http.c b/http.c\nindex 00a0e507633..8d616b5d60e 100644\n--- a/http.c\n+++ b/http.c\n@@ -86,6 +86,13 @@ static long curl_low_speed_time = -1;\n static int curl_ftp_no_epsv;\n static const char *curl_http_proxy;\n static const char *http_proxy_authmethod;\n+\n+static const char *http_proxy_ssl_cert;\n+static const char *http_proxy_ssl_key;\n+static const char *http_proxy_ssl_ca_info;\n+static struct credential proxy_cert_auth = CREDENTIAL_INIT;\n+static int proxy_ssl_cert_password_required;\n+\n static struct {\n \tconst char *name;\n \tlong curlauth_param;\n@@ -365,6 +372,20 @@ static int http_options(const char *var, const char *value, void *cb)\n \tif (!strcmp(\"http.proxyauthmethod\", var))\n \t\treturn git_config_string(&http_proxy_authmethod, var, value);\n \n+\tif (!strcmp(\"http.proxysslcert\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_cert, var, value);\n+\n+\tif (!strcmp(\"http.proxysslkey\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n+\n+\tif (!strcmp(\"http.proxysslcainfo\", var))\n+\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n+\n+\tif (!strcmp(\"http.proxysslcertpasswordprotected\", var)) {\n+\t\tproxy_ssl_cert_password_required = git_config_bool(var, value);\n+\t\treturn 0;\n+\t}\n+\n \tif (!strcmp(\"http.cookiefile\", var))\n \t\treturn git_config_pathname(&curl_cookie_file, var, value);\n \tif (!strcmp(\"http.savecookies\", var)) {\n@@ -565,6 +586,21 @@ static int has_cert_password(void)\n \treturn 1;\n }\n \n+#if LIBCURL_VERSION_NUM >= 0x073400\n+static int has_proxy_cert_password(void)\n+{\n+\tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n+\t\treturn 0;\n+\tif (!proxy_cert_auth.password) {\n+\t\tproxy_cert_auth.protocol = xstrdup(\"cert\");\n+\t\tproxy_cert_auth.username = xstrdup(\"\");\n+\t\tproxy_cert_auth.path = xstrdup(http_proxy_ssl_cert);\n+\t\tcredential_fill(&proxy_cert_auth);\n+\t}\n+\treturn 1;\n+}\n+#endif\n+\n #if LIBCURL_VERSION_NUM >= 0x071900\n static void set_curl_keepalive(CURL *c)\n {\n@@ -924,8 +960,14 @@ static CURL *get_curl_handle(void)\n #if LIBCURL_VERSION_NUM >= 0x073400\n \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n #endif\n-\t} else if (ssl_cainfo != NULL)\n-\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+\t} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {\n+\t\tif (ssl_cainfo != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\t\tif (http_proxy_ssl_ca_info != NULL)\n+\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);\n+#endif\n+\t}\n \n \tif (curl_low_speed_limit > 0 && curl_low_speed_time > 0) {\n \t\tcurl_easy_setopt(result, CURLOPT_LOW_SPEED_LIMIT,\n@@ -1018,9 +1060,18 @@ static CURL *get_curl_handle(void)\n \t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);\n #endif\n #if LIBCURL_VERSION_NUM >= 0x073400\n-\t\telse if (starts_with(curl_http_proxy, \"https\"))\n-\t\t\tcurl_easy_setopt(result,\n-\t\t\t\tCURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n+\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n+\t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n+\n+\t\t\tif (http_proxy_ssl_cert)\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n+\n+\t\t\tif (http_proxy_ssl_key)\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n+\n+\t\t\tif (has_proxy_cert_password())\n+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, proxy_cert_auth.password);\n+\t\t}\n #endif\n \t\tif (strstr(curl_http_proxy, \"://\"))\n \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n@@ -1230,6 +1281,12 @@ void http_cleanup(void)\n \t}\n \tssl_cert_password_required = 0;\n \n+\tif (proxy_cert_auth.password != NULL) {\n+\t\tmemset(proxy_cert_auth.password, 0, strlen(proxy_cert_auth.password));\n+\t\tFREE_AND_NULL(proxy_cert_auth.password);\n+\t}\n+\tproxy_ssl_cert_password_required = 0;\n+\n \tFREE_AND_NULL(cached_accept_language);\n }\n \n-- \ngitgitgadget\n\n"},{"id":"392869","messageId":"pull.559.v3.git.1583347206.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.v2.git.1582759438.gitgitgadget@gmail.com","subject":"[PATCH v3 0/2] Add HTTPS proxy SSL options (cert, key, cainfo)","fromName":"Jorge via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-03-04T18:40:04Z","receivedAt":"2020-03-04T18:40:13Z","isPatch":true,"sender":{"key":"griffin@gmx.es","avatar":null},"body":"Git currently supports connecting to proxies through HTTPS. However it does\nnot allow you to configure SSL options when connecting (i.e. client cert,\nkey, cainfo). These set of commits add the necessary options and\ndocumentation needed to support them.\n\nLibcurl already has support for this so changes are somewhat minimal.\n\nI ran the CI tests and verified manually with an HTTPS proxy that changes\nare working as expected. I didn't see integration tests under /t or tests\nthat verified libcurl integration. \n\n./bin-wrappers/git -c http.proxy=https://<PROXY-HOSTNAME> \\\n-c http.proxycert=<CERT> -c http.proxykey=<KEY> \\\nclone https://github.com/jalopezsilva/dotfiles.git  \n\nChanges since v2:\n=================\n\n * Merged the two initial commits as the second one was adding documentation\n   for the first.\n * Removed the SSL Cert password from configuration. I'm using a similar\n   function to has_cert_password to retrieve it if needed. \n * Better names and descriptions were given to the options. \n * Introduced another commit adding environment variable overrides for the\n   new options.\n\nJorge Lopez Silva (2):\n  http: add client cert for HTTPS proxies.\n  http: add environment variable for HTTPS proxy.\n\n Documentation/config/http.txt | 21 ++++++++++\n http.c                        | 74 ++++++++++++++++++++++++++++++++---\n 2 files changed, 90 insertions(+), 5 deletions(-)\n\n\nbase-commit: 51ebf55b9309824346a6589c9f3b130c6f371b8f\nPublished-As: https://github.com/gitgitgadget/git/releases/tag/pr-559%2Fjalopezsilva%2Fhttps_proxy_ssl_options-v3\nFetch-It-Via: git fetch https://github.com/gitgitgadget/git pr-559/jalopezsilva/https_proxy_ssl_options-v3\nPull-Request: https://github.com/gitgitgadget/git/pull/559\n\nRange-diff vs v2:\n\n 1:  a5d980e7501 ! 1:  e18b342819b http: add client cert for HTTPS proxies.\n     @@ -9,13 +9,44 @@\n      \n          A client certificate can provide an alternative way of authentication\n          instead of using 'ProxyAuthorization' or other more common methods of\n     -    authentication.\n     +    authentication.  Libcurl supports this functionality already so changes\n     +    are somewhat minimal. The feature is guarded by the first available\n     +    libcurl version that supports these options.\n      \n     -    Libcurl supports this functionality already. The feature is guarded by\n     -    the first available libcurl version that supports these options.\n     +    4 configuration options are added and documented, cert, key, cert\n     +    password protected and CA info. The CA info should be used to specify a\n     +    different CA path to validate the HTTPS proxy cert.\n      \n          Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n      \n     + diff --git a/Documentation/config/http.txt b/Documentation/config/http.txt\n     + --- a/Documentation/config/http.txt\n     + +++ b/Documentation/config/http.txt\n     +@@\n     + * `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)\n     + --\n     + \n     ++http.proxySSLCert::\n     ++\tThe pathname of a file that stores a client certificate to use to authenticate\n     ++\twith an HTTPS proxy.\n     ++\n     ++http.proxySSLKey::\n     ++\tThe pathname of a file that stores a private key to use to authenticate with\n     ++\tan HTTPS proxy.\n     ++\n     ++http.proxySSLCertPasswordProtected::\n     ++\tEnable Git's password prompt for the proxy SSL certificate.  Otherwise OpenSSL\n     ++\twill prompt the user, possibly many times, if the certificate or private key\n     ++\tis encrypted.\n     ++\n     ++http.proxySSLCAInfo::\n     ++\tPathname to the file containing the certificate bundle that should be used to\n     ++\tverify the proxy with when using an HTTPS proxy.\n     ++\n     + http.emptyAuth::\n     + \tAttempt authentication without seeking a username or password.  This\n     + \tcan be used to attempt GSS-Negotiate authentication without specifying\n     +\n       diff --git a/http.c b/http.c\n       --- a/http.c\n       +++ b/http.c\n     @@ -24,12 +55,11 @@\n       static const char *curl_http_proxy;\n       static const char *http_proxy_authmethod;\n      +\n     -+#if LIBCURL_VERSION_NUM >= 0x073400\n      +static const char *http_proxy_ssl_cert;\n      +static const char *http_proxy_ssl_key;\n     -+static const char *http_proxy_ssl_keypasswd;\n     -+#endif\n      +static const char *http_proxy_ssl_ca_info;\n     ++static struct credential proxy_cert_auth = CREDENTIAL_INIT;\n     ++static int proxy_ssl_cert_password_required;\n      +\n       static struct {\n       \tconst char *name;\n     @@ -38,23 +68,45 @@\n       \tif (!strcmp(\"http.proxyauthmethod\", var))\n       \t\treturn git_config_string(&http_proxy_authmethod, var, value);\n       \n     -+#if LIBCURL_VERSION_NUM >= 0x073400\n     -+\tif (!strcmp(\"http.proxycert\", var))\n     ++\tif (!strcmp(\"http.proxysslcert\", var))\n      +\t\treturn git_config_string(&http_proxy_ssl_cert, var, value);\n      +\n     -+\tif (!strcmp(\"http.proxykey\", var))\n     ++\tif (!strcmp(\"http.proxysslkey\", var))\n      +\t\treturn git_config_string(&http_proxy_ssl_key, var, value);\n      +\n     -+\tif (!strcmp(\"http.proxykeypass\", var))\n     -+\t\treturn git_config_string(&http_proxy_ssl_keypasswd, var, value);\n     -+\n     -+\tif (!strcmp(\"http.proxycainfo\", var))\n     ++\tif (!strcmp(\"http.proxysslcainfo\", var))\n      +\t\treturn git_config_string(&http_proxy_ssl_ca_info, var, value);\n     -+#endif\n     ++\n     ++\tif (!strcmp(\"http.proxysslcertpasswordprotected\", var)) {\n     ++\t\tproxy_ssl_cert_password_required = git_config_bool(var, value);\n     ++\t\treturn 0;\n     ++\t}\n      +\n       \tif (!strcmp(\"http.cookiefile\", var))\n       \t\treturn git_config_pathname(&curl_cookie_file, var, value);\n       \tif (!strcmp(\"http.savecookies\", var)) {\n     +@@\n     + \treturn 1;\n     + }\n     + \n     ++#if LIBCURL_VERSION_NUM >= 0x073400\n     ++static int has_proxy_cert_password(void)\n     ++{\n     ++\tif (http_proxy_ssl_cert == NULL || proxy_ssl_cert_password_required != 1)\n     ++\t\treturn 0;\n     ++\tif (!proxy_cert_auth.password) {\n     ++\t\tproxy_cert_auth.protocol = xstrdup(\"cert\");\n     ++\t\tproxy_cert_auth.username = xstrdup(\"\");\n     ++\t\tproxy_cert_auth.path = xstrdup(http_proxy_ssl_cert);\n     ++\t\tcredential_fill(&proxy_cert_auth);\n     ++\t}\n     ++\treturn 1;\n     ++}\n     ++#endif\n     ++\n     + #if LIBCURL_VERSION_NUM >= 0x071900\n     + static void set_curl_keepalive(CURL *c)\n     + {\n      @@\n       #if LIBCURL_VERSION_NUM >= 0x073400\n       \t\tcurl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);\n     @@ -82,16 +134,28 @@\n      +\t\telse if (starts_with(curl_http_proxy, \"https\")) {\n      +\t\t\tcurl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);\n      +\n     -+\t\t\tif (http_proxy_ssl_cert != NULL)\n     ++\t\t\tif (http_proxy_ssl_cert)\n      +\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);\n      +\n     -+\t\t\tif (http_proxy_ssl_key != NULL)\n     ++\t\t\tif (http_proxy_ssl_key)\n      +\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);\n      +\n     -+\t\t\tif (http_proxy_ssl_keypasswd != NULL)\n     -+\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);\n     -+\n     ++\t\t\tif (has_proxy_cert_password())\n     ++\t\t\t\tcurl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, proxy_cert_auth.password);\n      +\t\t}\n       #endif\n       \t\tif (strstr(curl_http_proxy, \"://\"))\n       \t\t\tcredential_from_url(&proxy_auth, curl_http_proxy);\n     +@@\n     + \t}\n     + \tssl_cert_password_required = 0;\n     + \n     ++\tif (proxy_cert_auth.password != NULL) {\n     ++\t\tmemset(proxy_cert_auth.password, 0, strlen(proxy_cert_auth.password));\n     ++\t\tFREE_AND_NULL(proxy_cert_auth.password);\n     ++\t}\n     ++\tproxy_ssl_cert_password_required = 0;\n     ++\n     + \tFREE_AND_NULL(cached_accept_language);\n     + }\n     + \n 2:  c40207a3928 ! 2:  086c5e59fb2 config: documentation for HTTPS proxy client cert.\n     @@ -1,10 +1,12 @@\n      Author: Jorge Lopez Silva <jalopezsilva@gmail.com>\n      \n     -    config: documentation for HTTPS proxy client cert.\n     +    http: add environment variable for HTTPS proxy.\n      \n     -    The commit adds 4 options, client cert, key, key password and CA info.\n     -    The CA info can be used to specify a different CA path to validate the\n     -    HTTPS proxy cert.\n     +    This commit adds four environment variables that can be used to\n     +    configure the proxy cert, proxy ssl key, the proxy cert password\n     +    protected flag, and the CA info for the proxy.\n     +\n     +    Documentation for the options was also updated.\n      \n          Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n      \n     @@ -12,23 +14,49 @@\n       --- a/Documentation/config/http.txt\n       +++ b/Documentation/config/http.txt\n      @@\n     - * `ntlm` - NTLM authentication (compare the --ntlm option of `curl(1)`)\n     - --\n       \n     -+http.proxycert::\n     -+\tFile indicating a client certificate to use to authenticate with an HTTPS proxy.\n     -+\n     -+http.proxykey::\n     -+\tFile indicating a private key to use to authenticate with an HTTPS proxy.\n     -+\n     -+http.proxykeypass::\n     -+\tWhen communicating to the proxy using TLS (using an HTTPS proxy), use this\n     -+\toption along `http.proxykey` to indicate a password for the key.\n     -+\n     -+http.proxycainfo::\n     -+\tFile containing the certificates to verify the proxy with when using an HTTPS\n     -+\tproxy.\n     -+\n     + http.proxySSLCert::\n     + \tThe pathname of a file that stores a client certificate to use to authenticate\n     +-\twith an HTTPS proxy.\n     ++\twith an HTTPS proxy. Can be overridden by the `GIT_PROXY_SSL_CERT` environment\n     ++\tvariable.\n     + \n     + http.proxySSLKey::\n     + \tThe pathname of a file that stores a private key to use to authenticate with\n     +-\tan HTTPS proxy.\n     ++\tan HTTPS proxy. Can be overridden by the `GIT_PROXY_SSL_KEY` environment\n     ++\tvariable.\n     + \n     + http.proxySSLCertPasswordProtected::\n     + \tEnable Git's password prompt for the proxy SSL certificate.  Otherwise OpenSSL\n     + \twill prompt the user, possibly many times, if the certificate or private key\n     +-\tis encrypted.\n     ++\tis encrypted. Can be overriden by the `GIT_PROXY_SSL_CERT_PASSWORD_PROTECTED`\n     ++\tenvironment variable.\n     + \n     + http.proxySSLCAInfo::\n     + \tPathname to the file containing the certificate bundle that should be used to\n     +-\tverify the proxy with when using an HTTPS proxy.\n     ++\tverify the proxy with when using an HTTPS proxy. Can be overriden by the\n     ++\t`GIT_PROXY_SSL_CAINFO` environment variable.\n     + \n       http.emptyAuth::\n       \tAttempt authentication without seeking a username or password.  This\n     - \tcan be used to attempt GSS-Negotiate authentication without specifying\n     +\n     + diff --git a/http.c b/http.c\n     + --- a/http.c\n     + +++ b/http.c\n     +@@\n     + \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n     + #endif\n     + \n     ++\tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n     ++\tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n     ++\tset_from_env(&http_proxy_ssl_ca_info, \"GIT_PROXY_SSL_CAINFO\");\n     ++\n     ++\tif (getenv(\"GIT_PROXY_SSL_CERT_PASSWORD_PROTECTED\"))\n     ++\t\tproxy_ssl_cert_password_required = 1;\n     ++\n     + \tif (getenv(\"GIT_CURL_FTP_NO_EPSV\"))\n     + \t\tcurl_ftp_no_epsv = 1;\n     + \n\n-- \ngitgitgadget\n"},{"id":"392870","messageId":"086c5e59fb2a94249fc42129222baf22d9f093b2.1583347206.git.gitgitgadget@gmail.com","threadId":"52865","inReplyTo":"pull.559.v3.git.1583347206.gitgitgadget@gmail.com","subject":"[PATCH v3 2/2] http: add environment variable for HTTPS proxy.","fromName":"Jorge Lopez Silva via GitGitGadget","fromEmail":"gitgitgadget@gmail.com","sentAt":"2020-03-04T18:40:06Z","receivedAt":"2020-03-04T18:40:14Z","isPatch":true,"sender":{"key":"name:Jorge Lopez Silva","avatar":null},"body":"From: Jorge Lopez Silva <jalopezsilva@gmail.com>\n\nThis commit adds four environment variables that can be used to\nconfigure the proxy cert, proxy ssl key, the proxy cert password\nprotected flag, and the CA info for the proxy.\n\nDocumentation for the options was also updated.\n\nSigned-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>\n---\n Documentation/config/http.txt | 12 ++++++++----\n http.c                        |  7 +++++++\n 2 files changed, 15 insertions(+), 4 deletions(-)\n\ndiff --git a/Documentation/config/http.txt b/Documentation/config/http.txt\nindex 7d398f9afba..3968fbb697a 100644\n--- a/Documentation/config/http.txt\n+++ b/Documentation/config/http.txt\n@@ -31,20 +31,24 @@ http.proxyAuthMethod::\n \n http.proxySSLCert::\n \tThe pathname of a file that stores a client certificate to use to authenticate\n-\twith an HTTPS proxy.\n+\twith an HTTPS proxy. Can be overridden by the `GIT_PROXY_SSL_CERT` environment\n+\tvariable.\n \n http.proxySSLKey::\n \tThe pathname of a file that stores a private key to use to authenticate with\n-\tan HTTPS proxy.\n+\tan HTTPS proxy. Can be overridden by the `GIT_PROXY_SSL_KEY` environment\n+\tvariable.\n \n http.proxySSLCertPasswordProtected::\n \tEnable Git's password prompt for the proxy SSL certificate.  Otherwise OpenSSL\n \twill prompt the user, possibly many times, if the certificate or private key\n-\tis encrypted.\n+\tis encrypted. Can be overriden by the `GIT_PROXY_SSL_CERT_PASSWORD_PROTECTED`\n+\tenvironment variable.\n \n http.proxySSLCAInfo::\n \tPathname to the file containing the certificate bundle that should be used to\n-\tverify the proxy with when using an HTTPS proxy.\n+\tverify the proxy with when using an HTTPS proxy. Can be overriden by the\n+\t`GIT_PROXY_SSL_CAINFO` environment variable.\n \n http.emptyAuth::\n \tAttempt authentication without seeking a username or password.  This\ndiff --git a/http.c b/http.c\nindex 8d616b5d60e..4283be9479b 100644\n--- a/http.c\n+++ b/http.c\n@@ -1211,6 +1211,13 @@ void http_init(struct remote *remote, const char *url, int proactive_auth)\n \t\tmax_requests = DEFAULT_MAX_REQUESTS;\n #endif\n \n+\tset_from_env(&http_proxy_ssl_cert, \"GIT_PROXY_SSL_CERT\");\n+\tset_from_env(&http_proxy_ssl_key, \"GIT_PROXY_SSL_KEY\");\n+\tset_from_env(&http_proxy_ssl_ca_info, \"GIT_PROXY_SSL_CAINFO\");\n+\n+\tif (getenv(\"GIT_PROXY_SSL_CERT_PASSWORD_PROTECTED\"))\n+\t\tproxy_ssl_cert_password_required = 1;\n+\n \tif (getenv(\"GIT_CURL_FTP_NO_EPSV\"))\n \t\tcurl_ftp_no_epsv = 1;\n \n-- \ngitgitgadget\n"}]}