Re: [RFC 0/2] Git-over-TLS (gits://) client side support
- From
Avery Pennarun <apenwarr@gmail.com>
- Date
- Jan 14, 2010, 20:46 UTC
- Message-ID
- <32541b131001141246o1f5ce816gc4a26b81343aaa2d@mail.gmail.com>
- In-Reply-To
- <20100114085124.GA10298@Knoppix>
On Thu, Jan 14, 2010 at 3:51 AM, Ilari Liusvaara <ilari.liusvaara@elisanet.fi> wrote:
> The client tries only one auth method instead of potentially trying > multiple. Witness the 'use verbose mode and check if it uses the key' > type stuff.
I believe this is a limitation of the client, not of the protocol. So a patch to the ssh client could fix this.
> OpenSSH? With the level of paranoia in it, I'd say good luck. And > it's not just client, its the server also (and especially the > server).
But you could fork it if you wanted. It's about as easy to convince me to install a different version of ssh than to install yet-another-security-server. (In fact, it might be easier to get me to put in a patched openssh; at least then I can trust that it's mostly openssh, and examine just what's different in your version.)
> And if you host the repo system too, you would get second key anyway > (and SSH is not too good at handling multiple keys).
I'm not really sure about this. ssh-add seems pretty easy.
Have fun,
Avery