git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH] http: store credential when PKI auth is used

From
John Szakmeister <john@szakmeister.net>
Date
Mar 6, 2021, 22:52 UTC
Message-ID
<20210306225253.87130-1-john@szakmeister.net>

We already looked for the PKI credentials in the credential store, but failed to approve it on success. Meaning, the PKI certificate password was never stored and git would request it on every connection to the remote. Let's complete the chain by storing the certificate password on success.

Signed-off-by: John Szakmeister <john@szakmeister.net>
---

I'm not sure if certificate passwords were not stored for some reason, but searching the archives I didn't see a mention of it. Hopefully this is acceptable. I did try this in an environment where we have client SSL certs and this made the user experience much better.

 http.c | 2 ++
 1 file changed, 2 insertions(+)
diff --git a/http.c b/http.c
index f8ea28bb2e..440890695f 100644
--- a/http.c
+++ b/http.c
@@ -1637,6 +1637,8 @@ static int handle_curl_result(struct slot_results *results)
 		credential_approve(&http_auth);
 		if (proxy_auth.password)
 			credential_approve(&proxy_auth);
+		if (cert_auth.password)
+			credential_approve(&cert_auth);
 		return HTTP_OK;
 	} else if (missing_target(results))
 		return HTTP_MISSING_TARGET;
-- 
2.30.1
Next: Jeff King
Message 1 of 4 in “http: store credential when PKI auth is used”
  1. http: store credential when PKI auth is usedJohn Szakmeister, Mar 6, 2021
  2. Jeff KingMar 10, 2021
  3. John SzakmeisterMar 12, 2021
  4. Jeff KingMar 12, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.