git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [RFC 0/2] Git-over-TLS (gits://) client side support

From
Avery Pennarun <apenwarr@gmail.com>
Date
Jan 13, 2010, 19:30 UTC
Message-ID
<32541b131001131130i6afae1a1xd3a70e5de5daa5cf@mail.gmail.com>
In-Reply-To
<20100113191802.GA8110@Knoppix>

On Wed, Jan 13, 2010 at 2:18 PM, Ilari Liusvaara <ilari.liusvaara@elisanet.fi> wrote:

Show 5 quoted lines
>> Please consider my objections revoked, other than the claim that
>> it could be done with stunnel, however ugly that would be.
>
> Only if you don't care about complexity introducing PKI would bring
> (yes, I read those manuals).

I think you're overstating the situation a bit here. You can use X.509 certificates without setting up a full PKI. Basically, an X.509 cert is just a public key with some extra crud thrown into the data file. You could validate it using a PKI, but you could also validate it by checking the verbatim public key just like ssh does. It's not elegant, but it works, and it's a worldwide standard.

(I don't know if stunnel does this type of validation... but *I've* done this with the openssl libraries, so I know it can be done.)

Show 5 quoted lines
>> Of course, you have another problem in that case...also I'd personally
>> like to rely on ssl client certificates when using https.
>
> And how many (relative) use client ceritificates with SSL? Keypairs with SSH?
> Why you think this is?

At least hundreds of thousands of people, including non-technical people, use X.509 client certificates and SSL in various big industries with high security requirements. That's why every major web browser supports them. In contrast, ssh is only ever used by techies, and there are fewer of those. Of course, as techies our informal observations might lead us to believe otherwise.

Furthermore, how many people who really want ssh-style keypairs (and thus refuse to use X.509 and PKI) can't just use ssh as their git transport? I don't actually understand what the goal is here.

Have fun,
Avery
Previous: Ilari LiusvaaraNext: Ilari Liusvaara
Message 13 of 28 in “[RFC 0/2] Git-over-TLS (gits://) client side support”
  1. Ilari LiusvaaraJan 13, 2010
  2. 1/2 Git-over-TLS (gits://) client side support (part 1 of 2)Ilari Liusvaara, Jan 13, 2010
  3. 2/2 Git-over-TLS (gits://) client side support (part 2 of 2)Ilari Liusvaara, Jan 13, 2010
  4. Alex RiesenJan 13, 2010
  5. Nguyen Thai Ngoc DuyJan 13, 2010
  6. Ilari LiusvaaraJan 13, 2010
  7. Andreas KreyJan 13, 2010
  8. Ilari LiusvaaraJan 13, 2010
  9. Andreas KreyJan 13, 2010
  10. Ilari LiusvaaraJan 13, 2010
  11. Andreas KreyJan 13, 2010
  12. Ilari LiusvaaraJan 13, 2010
  13. Avery PennarunJan 13, 2010
  14. Ilari LiusvaaraJan 13, 2010
  15. Avery PennarunJan 13, 2010
  16. Ilari LiusvaaraJan 13, 2010
  17. Avery PennarunJan 13, 2010
  18. Shawn O. PearceJan 13, 2010
  19. Ilari LiusvaaraJan 13, 2010
  20. Avery PennarunJan 13, 2010
  21. Ilari LiusvaaraJan 14, 2010
  22. Avery PennarunJan 14, 2010
  23. Ilari LiusvaaraJan 14, 2010
  24. Andreas KreyJan 13, 2010
  25. Ilari LiusvaaraJan 13, 2010
  26. Avery PennarunJan 13, 2010
  27. Ilari LiusvaaraJan 13, 2010
  28. Edward Z. YangJan 13, 2010

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.