git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: encrypted netrc for Git (was: [Wishlist] could git tell which password it is asking when asking a password.)

From
Jeff King <peff@peff.net>
Date
Jul 14, 2011, 15:00 UTC
Message-ID
<20110714150033.GA6797@sigill.intra.peff.net>
In-Reply-To
<87bowxt0sh.fsf_-_@lifelogs.com>
On Thu, Jul 14, 2011 at 09:05:50AM -0500, Ted Zlatanov wrote:
Show 20 quoted lines
> On Fri, 01 Jul 2011 12:04:02 -0500 Ted Zlatanov <tzz@lifelogs.com> wrote: 
> 
> TZ> On Fri, 01 Jul 2011 15:59:09 +0200 Rémi Vanicat <vanicat@debian.org> wrote: 
> 
> RV> It would be interesting also to plug some sort of password-safe unto
> RV> git, or some "git-agent". 
> 
> TZ> This would also be really nice.  ~/.netrc is not a great place to put
> TZ> passwords for the HTTP transport.  In GNU Emacs we have ~/.authinfo.gpg
> TZ> with the same content as ~/.netrc but encrypted by GPG and thus more
> TZ> secure (the user is either prompted for the password, if the file is
> TZ> encrypted symmetrically, or the user simply loads their private key into
> TZ> the GPG agent).  I believe all this can be done with the GPGME library.
> TZ> There's also the Secrets API on newer Gnome and KDE installs, which has
> TZ> a pretty nice D-Bus interface.
> 
> TZ> But is this a libcurl feature request?  Or can a Git plugin (an
> TZ> alternate HTTPS transport maybe?) handle it?
> 
> Ping?  I'd like to work on this if it seems like a feasible feature.
Check out:
  https://github.com/peff/git/commits/jk/http-auth

which provides an interface for getting credentials from external helpers.

I need to write docs for a few of the top commits before posting the patches to the list, but other than that, it should be fairly solid and usable. And I'd love to get feedback from somebody trying to write a new helper for it (i.e., to tell if the interface to the helpers is good enough).

-Peff
Previous: Ted ZlatanovNext: Ted Zlatanov
Message 13 of 15 in “[Wishlist] could git tell which password it is asking when asking a password.”
  1. Rémi VanicatJul 1, 2011
  2. Junio C HamanoJul 1, 2011
  3. Junio C HamanoJul 1, 2011
  4. Shawn PearceJul 1, 2011
  5. Junio C HamanoJul 1, 2011
  6. Rémi VanicatJul 1, 2011
  7. Ted ZlatanovJul 1, 2011
  8. Junio C HamanoJul 1, 2011
  9. Jeff KingJul 1, 2011
  10. Jeff KingJul 1, 2011
  11. Ted ZlatanovJul 1, 2011
  12. encrypted netrc for Git (was: [Wishlist] could git tell which password it is asking when asking a password.)Ted Zlatanov, Jul 14, 2011
  13. Jeff KingJul 14, 2011
  14. Ted ZlatanovJul 15, 2011
  15. Jeff KingJul 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.