git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC 0/2] Git-over-TLS (gits://) client side support

From
ILIlari Liusvaara <ilari.liusvaara@elisanet.fi>
Date
Jan 13, 2010, 21:04 UTC
Message-ID
<20100113210414.GA8535@Knoppix>
In-Reply-To
<32541b131001131213m75b4baefsc70a4cbf3c8431c8@mail.gmail.com>
On Wed, Jan 13, 2010 at 03:13:40PM -0500, Avery Pennarun wrote:
Show 5 quoted lines
> On Wed, Jan 13, 2010 at 3:06 PM, Ilari Liusvaara
> 
> Lots of people use it.  That was my point.  If it weren't important,
> web browser makers wouldn't bother putting it in; God knows they leave
> out a lot of other stuff that I'd like.
There are two kinds of "important". Actually important for users and
important for managers.
 
The latter tends to be implemented with much less real world need. And
one can usually tell which of those it was from usability of feature.
Show 10 quoted lines
> >> Furthermore, how many people who really want ssh-style keypairs (and
> >> thus refuse to use X.509 and PKI) can't just use ssh as their git
> >> transport?  I don't actually understand what the goal is here.
> >
> > As said, I got fed up with failure modes of SSH.
> 
> I think this is the answer that needs clarification.  What failure
> modes are these?  ssh doesn't seem to fail for me.  And github.com
> seems to be working rather well with a huge number of users and ssh
> authentication.

Those failure modes tend to be show up at setup phase. But when they show up, at worst I have seen ones that took hours to debug because of multitude of possible causes and no good information on what's wrong.

And don't get me started about multi-key setups.

SSH uses fixed sets of keys, which has inherent failure modes. And ssh server tends to be worse than the client (Github can avoid the server failure modes since they control the SSH server).

But not even github can avoid all the failure modes.
> If you're upset at the failure modes of ssh, is it possible to fix ssh
> instead of introducing Yet Another Tunneling Protocol?
No, those failure modes can't be solved in SSH.
-Ilari
Previous: Avery PennarunNext: Avery Pennarun
Message 16 of 28 in “[RFC 0/2] Git-over-TLS (gits://) client side support”
  1. Ilari LiusvaaraJan 13, 2010
  2. 1/2 Git-over-TLS (gits://) client side support (part 1 of 2)Ilari Liusvaara, Jan 13, 2010
  3. 2/2 Git-over-TLS (gits://) client side support (part 2 of 2)Ilari Liusvaara, Jan 13, 2010
  4. Alex RiesenJan 13, 2010
  5. Nguyen Thai Ngoc DuyJan 13, 2010
  6. Ilari LiusvaaraJan 13, 2010
  7. Andreas KreyJan 13, 2010
  8. Ilari LiusvaaraJan 13, 2010
  9. Andreas KreyJan 13, 2010
  10. Ilari LiusvaaraJan 13, 2010
  11. Andreas KreyJan 13, 2010
  12. Ilari LiusvaaraJan 13, 2010
  13. Avery PennarunJan 13, 2010
  14. Ilari LiusvaaraJan 13, 2010
  15. Avery PennarunJan 13, 2010
  16. Ilari LiusvaaraJan 13, 2010
  17. Avery PennarunJan 13, 2010
  18. Shawn O. PearceJan 13, 2010
  19. Ilari LiusvaaraJan 13, 2010
  20. Avery PennarunJan 13, 2010
  21. Ilari LiusvaaraJan 14, 2010
  22. Avery PennarunJan 14, 2010
  23. Ilari LiusvaaraJan 14, 2010
  24. Andreas KreyJan 13, 2010
  25. Ilari LiusvaaraJan 13, 2010
  26. Avery PennarunJan 13, 2010
  27. Ilari LiusvaaraJan 13, 2010
  28. Edward Z. YangJan 13, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.