git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git:// protocol over SSL/TLS

From
KKKonstantin Khomoutov <flatworm@users.sourceforge.net>
Date
Dec 27, 2013, 14:14 UTC
Message-ID
<20131227181406.aa6c3427b3e52c978205b8b2@domain007.com>
In-Reply-To
<CAErtv25JGxEs3ytAB019yajQooNs4k=bzukSE9kuHWAbir9-BQ@mail.gmail.com>

On Fri, 27 Dec 2013 19:58:19 +0600 Sergey Sharybin <sergey.vfx@gmail.com> wrote:

[...]
Show 9 quoted lines
> > Yes, but it will only be secure if you've managed to verify the
> > server's certificate and do trust its issuer (or a CA higher up the
> > cert's trust chain) -- people tend to confuse "encrypted" with
> > "secure" which is not at all the same thing.
> 
> We've got CA-signed certificate atm and it's about to be also
> EV-signed for our server (git.blender.org). So this is not gonna to be
> an issue. Cloning over https:// works fine, but we wanted to be sure
> all the bits are secure.
This setup sounds to be just the right thing.
> So guess we just need to recommend using https:// protocol instead of
> git:// for our users?

I think yes. HTTP[S] once was dumb and slow but now it should be comparable in speed to git:// as essentially using this protocol (which became "smart" [1]) means spawning a git server process once per fetch/push session and making the client and server Git processes communicate all by themselves, so HTTP is there for request routing, authentication and session setup while data transfer is carried out by Git processes themselves [2].

1. http://git-scm.com/blog/2010/03/04/smart-http.html
2. https://www.kernel.org/pub/software/scm/git/docs/git-http-backend.html
Previous: Pyeron, Jason J CTR (US)Next: Junio C Hamano
Message 19 of 21 in “git:// protocol over SSL/TLS”
  1. Sergey SharybinDec 27, 2013
  2. Andreas SchwabDec 27, 2013
  3. Konstantin KhomoutovDec 27, 2013
  4. Sergey SharybinDec 27, 2013
  5. Andreas SchwabDec 27, 2013
  6. Konstantin KhomoutovDec 27, 2013
  7. Sergey SharybinDec 27, 2013
  8. Matthieu MoyDec 27, 2013
  9. Sergey SharybinDec 27, 2013
  10. Konstantin KhomoutovDec 27, 2013
  11. Sergey SharybinDec 27, 2013
  12. Konstantin KhomoutovDec 27, 2013
  13. Jeff KingDec 28, 2013
  14. Bernhard R. LinkDec 27, 2013
  15. Sergey SharybinDec 28, 2013
  16. brian m. carlsonDec 28, 2013
  17. Andreas SchwabDec 27, 2013
  18. Pyeron, Jason J CTR (US)Dec 27, 2013
  19. Konstantin KhomoutovDec 27, 2013
  20. Junio C HamanoDec 27, 2013
  21. Ilari LiusvaaraDec 28, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.