git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/2] http.c: prompt for SSL client certificate password

From
Junio C Hamano <gitster@pobox.com>
Date
Jun 11, 2009, 23:56 UTC
Message-ID
<7vocsue354.fsf@alter.siamese.dyndns.org>
In-Reply-To
<ca433830906111600n2d45b5bdg3fb6e7c0a537ec78@mail.gmail.com>
Mark Lodato <lodatom@gmail.com> writes:
>> The user is always prompted, even if the certificate is not encrypted.
>> This should be fine; unencrypted certificates are rare and a security
>> risk anyway.

Hmm, "rare" is in the eyes of beholder. For automated settings, I would imagine that it is a necessary feature that we need to keep working. Of course the local box that keeps an unencrypted certificate used this way must be well protected to make it _not_ a security risk, but that is not an issue you are addressing with your patch anyway, so it is not nice to dismiss possible usability issues like this.

>> I did not create any tests because the existing http.sslcert option has
>> no tests to begin with.

Again, not nice. Not having tests in this particular patch may be Ok, as long as you or other people fix that deficiency with follow-up patches, but please don't be proud that you are following a bad example.

Previous: Daniel StenbergNext: Mark Lodato
Message 18 of 25 in “http.c: prompt for SSL client certificate password”
  1. 1/2 http.c: prompt for SSL client certificate passwordMark Lodato, May 28, 2009
  2. 2/2 http.c: add http.sslCertNoPass optionMark Lodato, May 28, 2009
  3. Mark LodatoJun 5, 2009
  4. Constantine PlotnikovJun 5, 2009
  5. Mark LodatoJun 7, 2009
  6. Mark LodatoJun 11, 2009
  7. Nanako ShiraishiJun 11, 2009
  8. Junio C HamanoJun 11, 2009
  9. Daniel StenbergJun 12, 2009
  10. Constantine PlotnikovJun 12, 2009
  11. Jakub NarebskiJun 12, 2009
  12. Rogan DawesJun 12, 2009
  13. Mark LodatoJun 12, 2009
  14. Mark LodatoJun 12, 2009
  15. Junio C HamanoJun 13, 2009
  16. Mark LodatoJun 13, 2009
  17. Daniel StenbergJun 13, 2009
  18. Junio C HamanoJun 11, 2009
  19. Mark LodatoJun 12, 2009
  20. Junio C HamanoJun 12, 2009
  21. Daniel StenbergJun 12, 2009
  22. Mark LodatoJun 12, 2009
  23. Junio C HamanoJun 13, 2009
  24. Mark LodatoJun 13, 2009
  25. Junio C HamanoJun 13, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.