git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http(s): automatically try NTLM authentication first

From
Jeff King <peff@peff.net>
Date
Feb 23, 2017, 19:35 UTC
Message-ID
<20170223193524.e7jsik4nwchjaeoe@sigill.intra.peff.net>
In-Reply-To
<xmqq1suo90za.fsf@gitster.mtv.corp.google.com>
On Thu, Feb 23, 2017 at 11:11:05AM -0800, Junio C Hamano wrote:
Show 19 quoted lines
> >> As far as Kerberos, this is a desirable feature to have enabled, with
> >> little downside.  I just don't know about the security of the NTLM part,
> >> and I don't think we should take this patch unless we're sure we know
> >> the consequences of it.
> >
> > Hmm. That would be a problem with my proposed patch 2 then, too, if only
> > because it turns the feature on by default in more places.
> >
> > If it _is_ dangerous to turn on all the time, I'd think we should
> > consider warning people in the http.emptyauth documentation.
> 
> I presume that we have finished discussing the security
> ramification, and if I am not mistaken the conclusion was that it
> could leak information if we turned on emptyAuth unconditionally
> when talking to a wrong server, and that the documentation needs an
> update to recommend those who use emptyAuth because they want to
> talk to Negotiate servers to use the http.<site>.emptyAuth form,
> limited to such servers, not a more generic http.emptyAuth, to avoid
> information leakage?

I don't know enough to evaluate the claims of emptyAuth being dangerous or not (nor do I use it myself or admin a server whose users need it). So I will let interested parties hash out whether it is a good idea or not, and I'm happy to drop my 2/2 for now.

If we are to make it more widely available, I would prefer something more like my 2/2 than always turning on http.emptyAuth, if only because it reduces the cost to people not using the feature. I'm happy to work more on the patch if we decide to go that route.

> If that is the case, let's take your 1/2 in the near-by thread
> without 2/2 (auto-enable emptyAuth) for now, as Dscho seems to have
> a case that may be helped by it.

Yes, I think 1/2 stands on its own. Whether it helps Dscho's case or not, it eliminates an HTTP round-trip for Basic-only servers, which I think is worth it.

-Peff
Previous: Junio C HamanoNext: David Turner
Message 16 of 38 in “http(s): automatically try NTLM authentication first”
  1. http(s): automatically try NTLM authentication firstDavid Turner, Feb 22, 2017
  2. Junio C HamanoFeb 22, 2017
  3. David TurnerFeb 22, 2017
  4. Junio C HamanoFeb 22, 2017
  5. Jeff KingFeb 22, 2017
  6. Johannes SchindelinFeb 23, 2017
  7. Junio C HamanoFeb 23, 2017
  8. Jeff KingFeb 23, 2017
  9. Junio C HamanoFeb 23, 2017
  10. Jeff KingFeb 23, 2017
  11. Johannes SchindelinFeb 25, 2017
  12. brian m. carlsonFeb 22, 2017
  13. Jeff KingFeb 22, 2017
  14. Junio C HamanoFeb 23, 2017
  15. Junio C HamanoFeb 23, 2017
  16. Jeff KingFeb 23, 2017
  17. David TurnerFeb 23, 2017
  18. brian m. carlsonFeb 23, 2017
  19. Mantas MikulėnasFeb 23, 2017
  20. Jeff KingFeb 22, 2017
  21. Junio C HamanoFeb 22, 2017
  22. Jeff KingFeb 22, 2017
  23. Junio C HamanoFeb 22, 2017
  24. Jeff KingFeb 22, 2017
  25. Junio C HamanoFeb 22, 2017
  26. Jeff KingFeb 22, 2017
  27. 2/2 http: add an "auto" mode for http.emptyauthJeff King, Feb 22, 2017
  28. David TurnerFeb 23, 2017
  29. Jeff KingFeb 23, 2017
  30. David TurnerFeb 23, 2017
  31. Jeff KingFeb 23, 2017
  32. David TurnerFeb 23, 2017
  33. Johannes SchindelinFeb 25, 2017
  34. Jeff KingFeb 25, 2017
  35. http: add an "auto" mode for http.emptyauthJeff King, Feb 25, 2017
  36. Junio C HamanoFeb 27, 2017
  37. Johannes SchindelinFeb 28, 2017
  38. 1/2 http: restrict auth methods to what the server advertisesJeff King, Feb 22, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.