git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GIT, libcurl and GSS-Negotiate

From
Carlos Martín Nieto <cmn@elego.de>
Date
May 12, 2014, 18:01 UTC
Message-ID
<1399917719.2595.5.camel@centaur.cmartin.tk>
In-Reply-To
<20140510210132.GD45511@vauxhall.crustytoothpaste.net>
On Sat, 2014-05-10 at 21:01 +0000, brian m. carlson wrote:
Show 21 quoted lines
> On Mon, May 05, 2014 at 12:21:33PM +0200, Ivo Bellin Salarin wrote:
> > Well, I'm on Windows.
> > using `git version 1.9.2.msysgit.0`.
> > 
> > You can find all the exchanges, recorded with wireshark, of the
> > following usecases:
> > * git vanilla (not working),
> > * VisualStudio2013 with libgit (working)
> > * curl (--ntlm, working)
> > * curl (--negotiate, not working)
> 
> Okay, so what it looks like is that for some reason, the server and
> libcurl refuse to connect with Negotiate authentication.  git uses
> CURLAUTH_ANY, and libcurl picks the best choice: Negotiate.  The
> difference between your setup and mine is that I'm using Negotiate with
> Kerberos 5, and you're using Negotiate with NTLM.
> 
> What it looks like is happening is that git is offering Negotiate data,
> and then your server is responding with a 401 Unauthorized.  libgit2
> (presumably using WinHTTP) continues in this case, retrying with a
> longer set of credential containing more data, but git gives up.

While libgit2 does use WinHTTP by default on Windows, Visual Studio overrides this and uses their own HTTP transport (which makes the .NET stack to handle it) because of the way the prefer to do things, with just the one persistent connection to TFS.

But details aside, the code Visual Studio uses to do authentication has nothing to do with any of the others.

   cmn
Previous: brian m. carlsonNext: Jeff King
Message 5 of 8 in “GIT, libcurl and GSS-Negotiate”
  1. Ivo Bellin SalarinApr 24, 2014
  2. brian m. carlsonApr 26, 2014
  3. Ivo Bellin SalarinMay 5, 2014
  4. brian m. carlsonMay 10, 2014
  5. Carlos Martín NietoMay 12, 2014
  6. Jeff KingMay 12, 2014
  7. brian m. carlsonMay 16, 2014
  8. Jeff KingMay 17, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.