git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC/PATCH] send-email: die if CA path doesn't exist

From
John Keeping <john@keeping.me.uk>
Date
Nov 20, 2015, 19:46 UTC
Message-ID
<20151120194651.GC21488@serenity.lan>
In-Reply-To
<20151120111848.GC11198@sigill.intra.peff.net>
On Fri, Nov 20, 2015 at 06:18:48AM -0500, Jeff King wrote:
Show 17 quoted lines
> On Tue, Nov 17, 2015 at 10:12:07PM +0000, John Keeping wrote:
> 
> > If the CA path isn't found it's most likely to indicate a
> > misconfiguration, in which case accepting any certificate is unlikely to
> > be the correct thing to do.
> 
> Yeah, this seems like a crazy default for security-sensitive code.
> 
> I suspect some people will see breakage from applying this (because
> their systems are broken and they did not know it), but that is a good
> thing.
> 
> For people who know their systems are broken and want to proceed anyway,
> what is the appropriate work-around? Obviously it involves disabling
> peer verification, but would we want to include instructions for doing
> so (either in the error message, or perhaps mentioning it in the commit
> message)?
The documentation already says:
	Set it to an empty string to disable certificate verification.

It's a bit lost in the middle of a paragraph but I think that is the best place for the detail of how to disable verification.

Having revisted the patch, I do think the message might be a bit terse, but I can't think of a reasonably concise way to point at the --smtp-ssl-cert-path argument as being the culprit.

Maybe we shouldn't worry too much about that, but should instead put the invalid path into the error message:

	die "CA path \"$smtp_ssl_cert_path\" does not exist.";
Previous: Jeff KingNext: Jeff King
Message 3 of 11 in “send-email: die if CA path doesn't exist”
  1. send-email: die if CA path doesn't existJohn Keeping, Nov 17, 2015
  2. Jeff KingNov 20, 2015
  3. John KeepingNov 20, 2015
  4. Jeff KingNov 24, 2015
  5. John KeepingNov 24, 2015
  6. Jeff KingNov 24, 2015
  7. John KeepingNov 24, 2015
  8. send-email: die if CA path doesn't existJohn Keeping, Nov 24, 2015
  9. Jeff KingNov 24, 2015
  10. John KeepingNov 25, 2015
  11. Jeff KingNov 25, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.