git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git:// protocol over SSL/TLS

From
BLBernhard R. Link <brl+git@mail.brlink.eu>
Date
Dec 27, 2013, 16:26 UTC
Message-ID
<20131227162606.GA6973@client.brlink.eu>
In-Reply-To
<CAErtv25URyB3znN1CMd87374NUjaSFvg=cee_-c=s8bB2j052A@mail.gmail.com>
* Sergey Sharybin <sergey.vfx@gmail.com> [131227 15:25]:
> Security in this case is about being sure everyone gets exactly the
> same repository as stored on the server, without any modifications to
> the sources cased by MITM.

Note that ssl (and thus https) only helps here against a resource-less man-in-the-middle. Getting catch-all CA-signed certificates is said to no longer available to everyone as easily as it was some years ago, but unless you allow only one private CA (and even there clients often fail) you still should assume everyone resourceful enough to still be able to do MITM.

        Bernhard R. Link
Previous: Jeff KingNext: Sergey Sharybin
Message 14 of 21 in “git:// protocol over SSL/TLS”
  1. Sergey SharybinDec 27, 2013
  2. Andreas SchwabDec 27, 2013
  3. Konstantin KhomoutovDec 27, 2013
  4. Sergey SharybinDec 27, 2013
  5. Andreas SchwabDec 27, 2013
  6. Konstantin KhomoutovDec 27, 2013
  7. Sergey SharybinDec 27, 2013
  8. Matthieu MoyDec 27, 2013
  9. Sergey SharybinDec 27, 2013
  10. Konstantin KhomoutovDec 27, 2013
  11. Sergey SharybinDec 27, 2013
  12. Konstantin KhomoutovDec 27, 2013
  13. Jeff KingDec 28, 2013
  14. Bernhard R. LinkDec 27, 2013
  15. Sergey SharybinDec 28, 2013
  16. brian m. carlsonDec 28, 2013
  17. Andreas SchwabDec 27, 2013
  18. Pyeron, Jason J CTR (US)Dec 27, 2013
  19. Konstantin KhomoutovDec 27, 2013
  20. Junio C HamanoDec 27, 2013
  21. Ilari LiusvaaraDec 28, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.