git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GSS-Negotiate authentication requires that all data fit into postbuffer

From
Jeff King <peff@peff.net>
Date
Oct 7, 2013, 12:02 UTC
Message-ID
<20131007120241.GC5792@sigill.intra.peff.net>
In-Reply-To
<20131006174959.GE3460@vauxhall.crustytoothpaste.net>
On Sun, Oct 06, 2013 at 05:50:00PM +0000, brian m. carlson wrote:
Show 17 quoted lines
> On Sun, Oct 06, 2013 at 05:38:24PM +0200, Daniel Stenberg wrote:
> > On Sun, 6 Oct 2013, brian m. carlson wrote:
> > 
> > >If there's a way to make Apache with mod_auth_kerb do that with
> > >curl, then it doesn't require a change to git, and I'm happy to
> > >make it on my end. But using the curl command line client, I don't
> > >see an Expect: 100-continue anywhere during the connection using
> > >Debian's curl 7.32.0-1.  Do I need to send a certain amount of
> > >data to see that behavior?
> > 
> > Correct, curl will enable "Expect: 100-continue" if the post size is
> > > 1024 bytes.
> 
> I've been able to reproduce this behavior with the curl command line
> client, but it looks like we disable Expect: 100-continue in git since
> some proxy servers are too stupid to understand it, according to commit
> 959dfcf.

Yeah, instead we try to make two separate requests, and assume that the first one clears the path for any further requests. Of course that doesn't work for auth methods that actually negotiate for each request.

We should probably make the "Expect" suppression optional for people who know they have working systems. It would be nice to trigger it automatically when people are using something like GSS, but that decision happens at the curl layer.

-Peff
Previous: brian m. carlsonNext: brian m. carlson
Message 7 of 8 in “GSS-Negotiate authentication requires that all data fit into postbuffer”
  1. brian m. carlsonOct 6, 2013
  2. Ilari LiusvaaraOct 6, 2013
  3. Daniel StenbergOct 6, 2013
  4. brian m. carlsonOct 6, 2013
  5. Daniel StenbergOct 6, 2013
  6. brian m. carlsonOct 6, 2013
  7. Jeff KingOct 7, 2013
  8. brian m. carlsonOct 7, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.