From: Constantine Plotnikov Date: Fri, 12 Jun 2009 15:38:29 GMT Subject: Re: [PATCH 1/2] http.c: prompt for SSL client certificate password Message-ID: <85647ef50906120838s37c186a9mec301e880b1a8a4e@mail.gmail.com> In-Reply-To: On Fri, Jun 12, 2009 at 11:56 AM, Daniel Stenberg wrote: > On Fri, 12 Jun 2009, Nanako Shiraishi wrote: > >> It would be ideal if you can inspect the certificate and decide if you >> need to ask for decrypting password before using it (and otherwise you don't >> ask). If you can't do that, probably you can introduce a config var that >> says "this certificate is encrypted", and bypass your new code if that >> config var isn't set. > > Is this really a common setup? Using an unencrypted private key sounds like > a really bad security situation to me. The certificate is never encrupted, > the passphrase is for the key. > For SSH using unencrypted private key is very common for scripting and cron jobs. For HTTPS situation looks like being worse since there is no analog of ssh-agent that covers at least some of scripting scenarios. Do we want to disable scripting for HTTPS? Constantine