{"thread":{"id":"58594","subject":"[PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","startedAt":"2022-10-10T17:39:55Z","lastAt":"2022-10-11T15:52:25Z","messageCount":7,"participants":["sndanailov@wired4ever.net","Junio C Hamano","brian m. carlson","Aaron Schrab","Philip Oakley","Sotir Danailov"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"464505","messageId":"20221010172859.13832-1-sndanailov@wired4ever.net","threadId":"58594","inReplyTo":null,"subject":"[PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"","fromEmail":"sndanailov@wired4ever.net","sentAt":"2022-10-10T17:28:59Z","receivedAt":"2022-10-10T17:39:55Z","isPatch":true,"sender":{"key":"sndanailov@wired4ever.net","avatar":null},"body":"From: Sotir Danailov <sndanailov@wired4ever.net>\n\nNew explanation for the difference between these values.\nIt's hard to understand what they do based only on the names.\n\nSigned-off-by: Sotir Danailov <sndanailov@wired4ever.net>\n---\n Documentation/git-send-email.txt | 7 +++++--\n 1 file changed, 5 insertions(+), 2 deletions(-)\n\ndiff --git a/Documentation/git-send-email.txt b/Documentation/git-send-email.txt\nindex 3290043053..4db32f05f0 100644\n--- a/Documentation/git-send-email.txt\n+++ b/Documentation/git-send-email.txt\n@@ -178,8 +178,11 @@ Sending\n \tfor `sendmail` in `/usr/sbin`, `/usr/lib` and $PATH.\n \n --smtp-encryption=<encryption>::\n-\tSpecify the encryption to use, either 'ssl' or 'tls'.  Any other\n-\tvalue reverts to plain SMTP.  Default is the value of\n+\tSpecify the encryption to use, either 'ssl' or 'tls'. Any other\n+\tvalue reverts to plain SMTP. The difference between the two for Git is\n+\tthat 'ssl' uses implicit encryption and defaults to port 465, 'tls'\n+\tuses explicit encryption and defaults to port 25. Other ports might be\n+\tused by the SMTP server. Default is the value of\n \t`sendemail.smtpEncryption`.\n \n --smtp-domain=<FQDN>::\n-- \n2.37.3\n\n"},{"id":"464526","messageId":"xmqqy1tn1ojw.fsf@gitster.g","threadId":"58594","inReplyTo":"20221010172859.13832-1-sndanailov@wired4ever.net","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2022-10-10T19:11:47Z","receivedAt":"2022-10-10T19:11:54Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"sndanailov@wired4ever.net writes:\n\n> From: Sotir Danailov <sndanailov@wired4ever.net>\n>\n> New explanation for the difference between these values.\n> It's hard to understand what they do based only on the names.\n\nTrue.  The names we use, 'ssl' and 'tls', emerged historically and\nare not the best ones in retrospect.\n\nIt may also help understanding if you mentioned STARTTLS somewhere\nin the description of \"explicit\" one, as (some) readers may be more\nfamiliar with that term than \"implicit vs explicit\".\n\n>  --smtp-encryption=<encryption>::\n> -\tSpecify the encryption to use, either 'ssl' or 'tls'.  Any other\n> -\tvalue reverts to plain SMTP.  Default is the value of\n> +\tSpecify the encryption to use, either 'ssl' or 'tls'. Any other\n> +\tvalue reverts to plain SMTP. The difference between the two for Git is\n> +\tthat 'ssl' uses implicit encryption and defaults to port 465, 'tls'\n> +\tuses explicit encryption and defaults to port 25. Other ports might be\n> +\tused by the SMTP server. Default is the value of\n>  \t`sendemail.smtpEncryption`.\n>  \n>  --smtp-domain=<FQDN>::\n\n\n"},{"id":"464529","messageId":"Y0R2AwKuXAVMP5Ma@tapette.crustytoothpaste.net","threadId":"58594","inReplyTo":"20221010172859.13832-1-sndanailov@wired4ever.net","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2022-10-10T19:44:03Z","receivedAt":"2022-10-10T19:44:09Z","isPatch":true,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2022-10-10 at 17:28:59, sndanailov@wired4ever.net wrote:\n> From: Sotir Danailov <sndanailov@wired4ever.net>\n> \n> New explanation for the difference between these values.\n> It's hard to understand what they do based only on the names.\n> \n> Signed-off-by: Sotir Danailov <sndanailov@wired4ever.net>\n> ---\n>  Documentation/git-send-email.txt | 7 +++++--\n>  1 file changed, 5 insertions(+), 2 deletions(-)\n> \n> diff --git a/Documentation/git-send-email.txt b/Documentation/git-send-email.txt\n> index 3290043053..4db32f05f0 100644\n> --- a/Documentation/git-send-email.txt\n> +++ b/Documentation/git-send-email.txt\n> @@ -178,8 +178,11 @@ Sending\n>  \tfor `sendmail` in `/usr/sbin`, `/usr/lib` and $PATH.\n>  \n>  --smtp-encryption=<encryption>::\n> -\tSpecify the encryption to use, either 'ssl' or 'tls'.  Any other\n> -\tvalue reverts to plain SMTP.  Default is the value of\n> +\tSpecify the encryption to use, either 'ssl' or 'tls'. Any other\n> +\tvalue reverts to plain SMTP. The difference between the two for Git is\n> +\tthat 'ssl' uses implicit encryption and defaults to port 465, 'tls'\n> +\tuses explicit encryption and defaults to port 25. Other ports might be\n> +\tused by the SMTP server. Default is the value of\n>  \t`sendemail.smtpEncryption`.\n\nThis is a definite improvement, but maybe we'd want to say that 'tls' is\nreally STARTTLS, while 'ssl' is always-on encryption over a dedicated\nport.  It might also be worth mentioning that the choice of name doesn't\naffect the actual protocol and version used and the user is almost\ncertainly using TLS either way.\n-- \nbrian m. carlson (he/him or they/them)\nToronto, Ontario, CA\n"},{"id":"464545","messageId":"xmqq35bvz10b.fsf@gitster.g","threadId":"58594","inReplyTo":"Y0R2AwKuXAVMP5Ma@tapette.crustytoothpaste.net","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2022-10-10T23:56:20Z","receivedAt":"2022-10-10T23:56:28Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n\n>>  --smtp-encryption=<encryption>::\n>> +\tSpecify the encryption to use, either 'ssl' or 'tls'. Any other\n>> +\tvalue reverts to plain SMTP. The difference between the two for Git is\n>> +\tthat 'ssl' uses implicit encryption and defaults to port 465, 'tls'\n>> +\tuses explicit encryption and defaults to port 25. Other ports might be\n>> +\tused by the SMTP server. Default is the value of\n>>  \t`sendemail.smtpEncryption`.\n>\n> This is a definite improvement, but maybe we'd want to say that 'tls' is\n> really STARTTLS, while 'ssl' is always-on encryption over a dedicated\n> port.  It might also be worth mentioning that the choice of name doesn't\n> affect the actual protocol and version used and the user is almost\n> certainly using TLS either way.\n\nSo, it is not really specifying \"the encryption\", rather the way to\nget into the encrypted communication.\n\nI think the prose is OK, as long as we are not adding the third\nvalue, at which time we may want to use enumeration instead.\n\n        Specify how SMTP connection should be entered into encrypted\n        mode.  The valid values are 'ssl' and 'tls'. Any other value\n        reverts to plain (unencrypted) SMTP.  'ssl' refers to \"implicit\"\n        encryption (sometimes calls SMTPS) that uses port 465 or 587 by\n        default. 'tls' refers to \"explicit\" encryption (often known as\n        STARTTLS) that uses port 25 by default.  Despite their names, it\n        is likely the user is using the newer TLS protocol, not the\n        deprecated SSL, for the actual encryption protocol either way.\n    +\n    Other ports might be used by the SMTP server. Default is the value of\n    `sendemail.smtpEncryption`.\n\nWe might want to\n\n * introduce synonyms implicit/smtps vs explicit/starttls and\n   deprecate the current confusing names over time?\n\n * error out when invalid value is given, instead of silently\n   talking plaintext SMTP?\n\n"},{"id":"464551","messageId":"Y0S2wyfUF1mZaryi@pug.qqx.org","threadId":"58594","inReplyTo":"xmqq35bvz10b.fsf@gitster.g","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"Aaron Schrab","fromEmail":"aaron@schrab.com","sentAt":"2022-10-11T00:20:19Z","receivedAt":"2022-10-11T00:20:33Z","isPatch":true,"sender":{"key":"aaron@schrab.com","avatar":"https://avatars.githubusercontent.com/u/39620?v=4"},"body":"At 16:56 -0700 10 Oct 2022, Junio C Hamano <gitster@pobox.com> wrote:\n>        Specify how SMTP connection should be entered into encrypted\n>        mode.  The valid values are 'ssl' and 'tls'. Any other value\n>        reverts to plain (unencrypted) SMTP.  'ssl' refers to \"implicit\"\n>        encryption (sometimes calls SMTPS) that uses port 465 or 587 by\n>        default.\n\nThere can be only one actual default port for each of the settings and \nhere that is 465.\n\nAlso, port 587 belongs with the 'tls' value. Perhaps saying something \nlike:\n\n     uses port 25 by default, but port 587 is often used as well.\n\n>        'tls' refers to \"explicit\" encryption (often known as\n>        STARTTLS) that uses port 25 by default.  Despite their names, it\n>        is likely the user is using the newer TLS protocol, not the\n>        deprecated SSL, for the actual encryption protocol either way.\n"},{"id":"464613","messageId":"69ba0bb5-19c1-e54e-bc06-515a17380494@iee.email","threadId":"58594","inReplyTo":"Y0S2wyfUF1mZaryi@pug.qqx.org","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"Philip Oakley","fromEmail":"philipoakley@iee.email","sentAt":"2022-10-11T14:06:17Z","receivedAt":"2022-10-11T14:07:06Z","isPatch":true,"sender":{"key":"philipoakley@iee.email","avatar":"https://avatars.githubusercontent.com/u/914343?v=4"},"body":"On 11/10/2022 01:20, Aaron Schrab wrote:\n> At 16:56 -0700 10 Oct 2022, Junio C Hamano <gitster@pobox.com> wrote:\n>>        Specify how SMTP connection should be entered into encrypted\n>>        mode.  The valid values are 'ssl' and 'tls'. Any other value\n>>        reverts to plain (unencrypted) SMTP.  'ssl' refers to \"implicit\"\n>>        encryption (sometimes calls SMTPS) that uses port 465 or 587 by\n>>        default.\n>\n> There can be only one actual default port for each of the settings and\n> here that is 465.\n>\n> Also, port 587 belongs with the 'tls' value. Perhaps saying something\n> like:\n>\n>     uses port 25 by default, but port 587 is often used as well.\n>\n>>        'tls' refers to \"explicit\" encryption (often known as\n>>        STARTTLS) that uses port 25 by default.  Despite their names, it\n>>        is likely the user is using the newer TLS protocol, not the\n>>        deprecated SSL, for the actual encryption protocol either way.\n\nI support the feeling that the documentation needs a bit of updating.\n\nI found that I just couldn't manage to set up a send-email configuration\nfor one of my ISPs who was using non-default settings, and I never\nmanaged to work out what was required, or decode if the script was\ntrying to enforce the default in some cases (i.e. it wasn't a 'default'\nthat could be changed!).\n\nThat ISP has recently consolidated its options (it has many legacy UK\nemail domains) to limit it's exposure to security holes, so I may retry\nat some point(not this month), but it can be frustrating trying to debug\nthese failures in setups.\n\nPhilip\n\n\n"},{"id":"464619","messageId":"7f62a170-c3cf-0911-5c76-2b2565674189@wired4ever.net","threadId":"58594","inReplyTo":"Y0S2wyfUF1mZaryi@pug.qqx.org","subject":"Re: [PATCH] docs: git-send-email: difference between ssl and tls smtp-encryption","fromName":"Sotir Danailov","fromEmail":"sndanailov@wired4ever.net","sentAt":"2022-10-11T15:49:46Z","receivedAt":"2022-10-11T15:52:25Z","isPatch":true,"sender":{"key":"sndanailov@wired4ever.net","avatar":null},"body":"On Tue 11 Oct 2022 02:20, Aaron Schrab wrote:\n> uses port 25 by default, but port 587 is often used as well\n\nWell, I was trying to explain that the script would default to that port.\nI like your idea as well, but I'm not sure if it will make things clearer.\nI'm making a second version of the patch now. I will try to balance out\nall of the ideas into something I feel might be easy to follow.\n"}]}