git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 0/1] send-email: add client certificate options

From
David Timber <dxdt@dev.snart.me>
Date
Mar 2, 2026, 03:16 UTC
Message-ID
<20260302032048.260209-1-dxdt@dev.snart.me>
In-Reply-To
<xmqqo6lb4fuy.fsf@gitster.g>
I'm sorry that I missed last week's submission deadline.
On 2/21/26 01:35, Junio C Hamano wrote:
Show 5 quoted lines
> Shouldn't there be a word "require" somewhere in the above to
> clarify why a user may want to use this option?  A server may
> optionally verify a certificate only when it is given one, but if it
> lets us do what we want without such verification, we do not have
> much incentive to give them a certificate.
RFC 8446 section 4.3.2:
> The client MUST send a Certificate message if and only if the server
> has requested client authentication via a CertificateRequest message
> (Section 4.3.2).

In other words, the client won't send its cert to the server unless requested by the server. So, the client presenting its cert to the server in the client hello from the get-go is in violation of this requirement. I reflected that in the reroll.

Also, removed the `$ret{SSL_use_cert} = 1;` line in the code to be in line with the requirement. That line was confusing and unnecessary in the first place. Whether to use a client cert or not should be up to the underlying implementation to decide.

Removed the whole PKCS#12 vs PEM debacle in the change as I reckon it's a behaviour that could change overnight without a warning. Feels kind of defensive, but a reasonable change all things considered. Users affected by such library behaviour change can always refer to the manual.

David Timber (1):
  send-email: add client certificate options
 Documentation/config/sendemail.adoc | 16 ++++++++++
 Documentation/git-send-email.adoc   | 19 ++++++++++++
 git-send-email.perl                 | 47 ++++++++++++++++++++++-------
 3 files changed, 71 insertions(+), 11 deletions(-)
-- 
2.53.0.1.ga224b40d3f.dirty
Previous: Junio C HamanoNext: David Timber
Message 6 of 10 in “send-email: add client certificate options”
  1. 0/1 send-email: add client certificate optionsDavid Timber, Feb 20, 2026
  2. 1/1 send-mail: add client certificate optionsDavid Timber, Feb 20, 2026
  3. Junio C HamanoFeb 20, 2026
  4. David TimberFeb 21, 2026
  5. Junio C HamanoFeb 26, 2026
  6. 0/1 send-email: add client certificate optionsDavid Timber, Mar 2, 2026
  7. 1/1 send-email: add client certificate optionsDavid Timber, Mar 2, 2026
  8. Junio C HamanoMar 2, 2026
  9. David TimberMar 4, 2026
  10. Junio C HamanoFeb 20, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.