git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: git:// protocol over SSL/TLS

From
KKKonstantin Khomoutov <flatworm@users.sourceforge.net>
Date
Dec 27, 2013, 14:39 UTC
Message-ID
<20131227183958.b8e55d7e3c8c38b46137ea9c@domain007.com>
In-Reply-To
<CAErtv25URyB3znN1CMd87374NUjaSFvg=cee_-c=s8bB2j052A@mail.gmail.com>

On Fri, 27 Dec 2013 20:25:16 +0600 Sergey Sharybin <sergey.vfx@gmail.com> wrote:

Show 8 quoted lines
> Security in this case is about being sure everyone gets exactly the
> same repository as stored on the server, without any modifications to
> the sources cased by MITM.
> 
> As for "smart" http, this seems pretty much cool.However, we're
> currently using lighthttpd, so it might be an issue. We'll check on
> whether "smart" http is used there, and if not guess it wouldn't be a
> big deal to switch to apache.

The web server software has nothing to do with HTTP[S] used by Git being "smart", I think, it just has to be set up properly.

As discussed in an earlier thread here, a good indication of the dumb version of the protocol being in use is no display of the fetching progress on the client while doing `git clone` because this information (like "compressing objects ..." etc) is sent by the server-side Git process which is only there if HTTP[S] "was smart". Otherwise the client just GETs packs of objects, traverses them, GETs more and so on, so batches of HTTP GET requests correlating to clone sessions in the web server logs should also be indicative of the problem.

Previous: Sergey SharybinNext: Sergey Sharybin
Message 10 of 21 in “git:// protocol over SSL/TLS”
  1. Sergey SharybinDec 27, 2013
  2. Andreas SchwabDec 27, 2013
  3. Konstantin KhomoutovDec 27, 2013
  4. Sergey SharybinDec 27, 2013
  5. Andreas SchwabDec 27, 2013
  6. Konstantin KhomoutovDec 27, 2013
  7. Sergey SharybinDec 27, 2013
  8. Matthieu MoyDec 27, 2013
  9. Sergey SharybinDec 27, 2013
  10. Konstantin KhomoutovDec 27, 2013
  11. Sergey SharybinDec 27, 2013
  12. Konstantin KhomoutovDec 27, 2013
  13. Jeff KingDec 28, 2013
  14. Bernhard R. LinkDec 27, 2013
  15. Sergey SharybinDec 28, 2013
  16. brian m. carlsonDec 28, 2013
  17. Andreas SchwabDec 27, 2013
  18. Pyeron, Jason J CTR (US)Dec 27, 2013
  19. Konstantin KhomoutovDec 27, 2013
  20. Junio C HamanoDec 27, 2013
  21. Ilari LiusvaaraDec 28, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.