git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GIT, libcurl and GSS-Negotiate

From
brian m. carlson <sandals@crustytoothpaste.net>
Date
Apr 26, 2014, 17:47 UTC
Message-ID
<20140426174718.GC238861@vauxhall.crustytoothpaste.net>
In-Reply-To
<CAPc4eF__gWMy=E-8tdpMn_irA4m7mYF3=cwN6JeAqJsdPshNLw@mail.gmail.com>
On Thu, Apr 24, 2014 at 07:17:36PM +0200, Ivo Bellin Salarin wrote:
Show 19 quoted lines
> To shortly resume it, the problem is that:
> * when the authentication method (WWW-Authenticate) is Negotiate AND
> * when the server proposes a NTLMSSP_CHALLENGE in response of the
> client's NTLMSSP_NEGOTIATE,
> => libcurl yields an "Authentication problem. Ignoring this.\n"
> And the communication is closed.
> 
> At this point, in a normal communication, the client should send a
> NTLMSSP_AUTH containing a Kerberos ticket.
> 
> Having seen the libcurl source code, I think we're passing through the
> lines  from 776 to 780 of
> [http.c](https://github.com/bagder/curl/blob/2e57c7e0fcfb9214b2a9dfa8b3da258ded013b8a/lib/http.c).
> Some guy, on the github issue page, has suggested that this could be
> related to an update of libcurl, when git was at its 1.8.2 version.
> 
> I'm not debugging libcurl, and I can't reproduce this problem @home.
> So, has somebody already experienced the same problem? Is there a
> solution?

I'm personally using Git with GSS-Negotiate (and MIT Kerberos 5) and it does seem to work correctly for me. For large pushes, your server (and any intermediate proxies) will need to support 100 Continue properly, as there's simply no other way to make it work.

What version of curl are you using (and what distro if you didn't compile it yourself)? Also, can you post output of an attempt to push with GIT_CURL_VERBOSE=1?

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Previous: Ivo Bellin SalarinNext: Ivo Bellin Salarin
Message 2 of 8 in “GIT, libcurl and GSS-Negotiate”
  1. Ivo Bellin SalarinApr 24, 2014
  2. brian m. carlsonApr 26, 2014
  3. Ivo Bellin SalarinMay 5, 2014
  4. brian m. carlsonMay 10, 2014
  5. Carlos Martín NietoMay 12, 2014
  6. Jeff KingMay 12, 2014
  7. brian m. carlsonMay 16, 2014
  8. Jeff KingMay 17, 2014

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.