git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC 0/2] Git-over-TLS (gits://) client side support

From
ILIlari Liusvaara <ilari.liusvaara@elisanet.fi>
Date
Jan 14, 2010, 08:51 UTC
Message-ID
<20100114085124.GA10298@Knoppix>
In-Reply-To
<32541b131001131551m38ff02acpdd08d9f0562ac84d@mail.gmail.com>
On Wed, Jan 13, 2010 at 06:51:03PM -0500, Avery Pennarun wrote:
Show 9 quoted lines
> On Wed, Jan 13, 2010 at 6:00 PM, Ilari Liusvaara
> <ilari.liusvaara@elisanet.fi> wrote:
> > On Wed, Jan 13, 2010 at 05:03:45PM -0500, Avery Pennarun wrote:
> >
> > No client-side fallbacks, key auth works pseudonymously. That takes
> > care of them pretty well.
> 
> Perhaps I'm being dense, but I don't understand what you mean by
> either of those.

The client tries only one auth method instead of potentially trying multiple. Witness the 'use verbose mode and check if it uses the key' type stuff.

With keypair auth, the server can accept arbitrary (valid) keypair, but only limited set have special priviledges -> Cuts down significantly on "why this doesn't accept the key" problems (the keyid is usually printed on denied access).

Show 11 quoted lines
> >> If you solve your main
> >> annoyances with ssh, how do you know you won't introduce any new
> >> annoying failure modes?
> >
> > Ensuring that at least some information make back to client (presuably
> > enough to figure out the problem).
> 
> Unfortunately revealing information like that is a compromise; it
> helps attackers as well as legitimate users.  It's the same reason
> login prints "invalid username or password" instead of choosing
> between "invalid username" and "invalid password."

Yeah. Sometimes one must chose balance between being helpful to users and being helpful for attackers.

Show 9 quoted lines
> >> *Why* can't ssh be fixed to solve the  problem?
> >
> > Client side fallbacks (may be desired or not!), service not being
> > able to intervene on wheither to allow client or not in case of
> > keypair auth.
> 
> I don't understand that answer.  Couldn't ssh be patched to do
> whatever you want?  Particularly if it's just better (optional)
> diagnostics, you'd think someone would accept the patch for that.

OpenSSH? With the level of paranoia in it, I'd say good luck. And it's not just client, its the server also (and especially the server).

Show 6 quoted lines
> >>  Will I have to generate and manage yet another new set of
> >> keys to use the new system?
> >
> > Yes.
> 
> Ouch.

Well, usually that means one keypair to generate and exchanging keyids.

And if you host the repo system too, you would get second key anyway (and SSH is not too good at handling multiple keys).

Show 5 quoted lines
> > Well, if you like SSH more, then use ssh://...
> 
> I'm just looking for a justification for why I *shouldn't* like ssh
> more.  Is the only reason the fact that it might be easier to
> initially configure the key exchange?

And besides, gits:// is for host multiple repos type stuff, not for private repos on your account (use the ssh:// for those, and there the failure modes of SSH matter much less).

-Ilari
Previous: Avery PennarunNext: Avery Pennarun
Message 21 of 28 in “[RFC 0/2] Git-over-TLS (gits://) client side support”
  1. Ilari LiusvaaraJan 13, 2010
  2. 1/2 Git-over-TLS (gits://) client side support (part 1 of 2)Ilari Liusvaara, Jan 13, 2010
  3. 2/2 Git-over-TLS (gits://) client side support (part 2 of 2)Ilari Liusvaara, Jan 13, 2010
  4. Alex RiesenJan 13, 2010
  5. Nguyen Thai Ngoc DuyJan 13, 2010
  6. Ilari LiusvaaraJan 13, 2010
  7. Andreas KreyJan 13, 2010
  8. Ilari LiusvaaraJan 13, 2010
  9. Andreas KreyJan 13, 2010
  10. Ilari LiusvaaraJan 13, 2010
  11. Andreas KreyJan 13, 2010
  12. Ilari LiusvaaraJan 13, 2010
  13. Avery PennarunJan 13, 2010
  14. Ilari LiusvaaraJan 13, 2010
  15. Avery PennarunJan 13, 2010
  16. Ilari LiusvaaraJan 13, 2010
  17. Avery PennarunJan 13, 2010
  18. Shawn O. PearceJan 13, 2010
  19. Ilari LiusvaaraJan 13, 2010
  20. Avery PennarunJan 13, 2010
  21. Ilari LiusvaaraJan 14, 2010
  22. Avery PennarunJan 14, 2010
  23. Ilari LiusvaaraJan 14, 2010
  24. Andreas KreyJan 13, 2010
  25. Ilari LiusvaaraJan 13, 2010
  26. Avery PennarunJan 13, 2010
  27. Ilari LiusvaaraJan 13, 2010
  28. Edward Z. YangJan 13, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.