git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/2] http.c: prompt for SSL client certificate password

From
RDRogan Dawes <lists@dawes.za.net>
Date
Jun 12, 2009, 21:49 UTC
Message-ID
<4A32CD83.1090801@dawes.za.net>
In-Reply-To
<m3vdn12y6y.fsf@localhost.localdomain>
Jakub Narebski wrote:
Show 9 quoted lines
>> For SSH using unencrypted private key is very common for scripting and
>> cron jobs. For HTTPS situation looks like being worse since there is
>> no analog of ssh-agent that covers at least some of scripting
>> scenarios. Do we want to disable scripting for HTTPS?
> 
> Actually you can use _encrypted_ private keys together with ssh-agent
> and for example keychain helper for scripting.  You have to provide
> password to all listed private keys only once at login.  I wonder if
> something like this would be possible for HTTP certificates...
I wonder if it might be possible using a PKCS#11 interface?

e.g. there are various "software" PKCS#11 implementations (<http://trac.opendnssec.org/wiki/SoftHSM> springs to mind).

If you store your keys in the PKCS#11 store, and unlock them prior to calling git, then the OpenSSL library might be able to access them without a passphrase. Locking the PKCS#11 store would then secure the keys.

A little cumbersome, but possibly workable.
Rogan
Previous: Jakub NarebskiNext: Mark Lodato
Message 12 of 25 in “http.c: prompt for SSL client certificate password”
  1. 1/2 http.c: prompt for SSL client certificate passwordMark Lodato, May 28, 2009
  2. 2/2 http.c: add http.sslCertNoPass optionMark Lodato, May 28, 2009
  3. Mark LodatoJun 5, 2009
  4. Constantine PlotnikovJun 5, 2009
  5. Mark LodatoJun 7, 2009
  6. Mark LodatoJun 11, 2009
  7. Nanako ShiraishiJun 11, 2009
  8. Junio C HamanoJun 11, 2009
  9. Daniel StenbergJun 12, 2009
  10. Constantine PlotnikovJun 12, 2009
  11. Jakub NarebskiJun 12, 2009
  12. Rogan DawesJun 12, 2009
  13. Mark LodatoJun 12, 2009
  14. Mark LodatoJun 12, 2009
  15. Junio C HamanoJun 13, 2009
  16. Mark LodatoJun 13, 2009
  17. Daniel StenbergJun 13, 2009
  18. Junio C HamanoJun 11, 2009
  19. Mark LodatoJun 12, 2009
  20. Junio C HamanoJun 12, 2009
  21. Daniel StenbergJun 12, 2009
  22. Mark LodatoJun 12, 2009
  23. Junio C HamanoJun 13, 2009
  24. Mark LodatoJun 13, 2009
  25. Junio C HamanoJun 13, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.