git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] git-imap-send.txt: remove the use of sslverify=false

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 24, 2013, 17:18 UTC
Message-ID
<7vr4hzetki.fsf@alter.siamese.dyndns.org>
In-Reply-To
<51758EE8.7030800@gmail.com>
Barbu Paul - Gheorghe <barbu.paul.gheorghe@gmail.com> writes:
Show 27 quoted lines
> Since SSL provides no protection if the certificates aren't verified it's
> better not to include sslverify=false in the examples.
> Also in the post 1.8.2.1 era git is able to properly verify the validity of a
> certificate as well it's origin.
>
> Signed-off-by: Barbu Paul - Gheorghe <barbu.paul.gheorghe@gmail.com>
> ---
>  Documentation/git-imap-send.txt | 2 --
>  1 file changed, 2 deletions(-)
>
> diff --git a/Documentation/git-imap-send.txt b/Documentation/git-imap-send.txt
> index 875d283..0d72977 100644
> --- a/Documentation/git-imap-send.txt
> +++ b/Documentation/git-imap-send.txt
> @@ -108,7 +108,6 @@ Using direct mode with SSL:
>      user = bob
>      pass = p4ssw0rd
>      port = 123
> -    sslverify = false
>  ..........................
>   @@ -123,7 +122,6 @@ to specify your account settings:
>  	host = imaps://imap.gmail.com
>  	user = user@gmail.com
>  	port = 993
> -	sslverify = false
>  ---------
>   You might need to instead use: folder = "[Google Mail]/Drafts" if you get an error
It is amusing that an MTA can mangle such a short patch this badly.

Count the number of preimage lines in the first hunk and you see only 5 lines but you claim it has 7. Where did the other two go? The second hunk has the same problem. "@@" that introduces the second hunk is not at the leftmost column. Where did the leading SP come from?

The examples in the documentation are primarily to demonstrate how the supported configurations and options can be used and for what purpose. its secondary purpose is to nudge the readers into the best practice.

So I'd suggest a patch that does these things instead of just removing these two:

 (0) Remove the duplication between the Examples header with ~~~~~~
     underline and the EXAMPLE header with ------ underline.
 (1) Use the second hunk of your patch to remove sslverify=false
     from that imap.gmail.com example.  As a public service, it is
     unlikely that the server side is configured to throw a
     certificate that does not verify at you.
 (2) Instead of removing sslverify=false in the imap.example.com
     example, comment it out like this:
     -	sslverify = false
     +	; sslverify = false
     Then mention that the user may want to use sslverify=false
     while troubleshooting, if he suspects that the reason he is
     having trouble connecting is because the certificate he uses at
     the private server at example.com he is trying to set up (or
     has set up) may not be verified correctly.
Previous: Barbu Paul - Gheorghe
Message 8 of 8 in “git-imap-send.txt: remove the use of sslverify=false in GMail example”
  1. git-imap-send.txt: remove the use of sslverify=false in GMail exampleBarbu Paul - Gheorghe, Apr 10, 2013
  2. Junio C HamanoApr 10, 2013
  3. Barbu Paul - GheorgheApr 11, 2013
  4. Simon RuderichApr 11, 2013
  5. Barbu Paul - GheorgheApr 11, 2013
  6. Simon RuderichApr 20, 2013
  7. git-imap-send.txt: remove the use of sslverify=falseBarbu Paul - Gheorghe, Apr 22, 2013
  8. Junio C HamanoApr 24, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.