git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: encrypted netrc for Git

From
Ted Zlatanov <tzz@lifelogs.com>
Date
Jul 15, 2011, 17:08 UTC
Message-ID
<8762n379pa.fsf@lifelogs.com>
In-Reply-To
<20110714150033.GA6797@sigill.intra.peff.net>
On Thu, 14 Jul 2011 11:00:33 -0400 Jeff King <peff@peff.net> wrote: 
JK> On Thu, Jul 14, 2011 at 09:05:50AM -0500, Ted Zlatanov wrote:

TZ> This would also be really nice. ~/.netrc is not a great place to put TZ> passwords for the HTTP transport. In GNU Emacs we have ~/.authinfo.gpg TZ> with the same content as ~/.netrc but encrypted by GPG and thus more TZ> secure (the user is either prompted for the password, if the file is TZ> encrypted symmetrically, or the user simply loads their private key into TZ> the GPG agent). I believe all this can be done with the GPGME library. TZ> There's also the Secrets API on newer Gnome and KDE installs, which has TZ> a pretty nice D-Bus interface.

JK> Check out:
JK>   https://github.com/peff/git/commits/jk/http-auth

JK> which provides an interface for getting credentials from external JK> helpers.

The API is good, but it's not clear from the docs how to configure credential helpers from the user side. From the tests it looks like you set GIT_ASKPASS to them, is that right? And you can also set credential.helper?

Where do those helpers fit with the .netrc file? Are they called before or after or instead of the .netrc parse?

Linking these with external libraries like GPGME and the Secrets API will be pretty easy and improve the user experience. So I'll be glad to work on it and provide you with feedback. Would you be interested in pushing your patches further after the testing? They seem pretty complete.

I'm off-line for the next 10 days or so; I'll start testing when I get back.

Thanks for your help Ted

Previous: Jeff KingNext: Jeff King
Message 14 of 15 in “[Wishlist] could git tell which password it is asking when asking a password.”
  1. Rémi VanicatJul 1, 2011
  2. Junio C HamanoJul 1, 2011
  3. Junio C HamanoJul 1, 2011
  4. Shawn PearceJul 1, 2011
  5. Junio C HamanoJul 1, 2011
  6. Rémi VanicatJul 1, 2011
  7. Ted ZlatanovJul 1, 2011
  8. Junio C HamanoJul 1, 2011
  9. Jeff KingJul 1, 2011
  10. Jeff KingJul 1, 2011
  11. Ted ZlatanovJul 1, 2011
  12. encrypted netrc for Git (was: [Wishlist] could git tell which password it is asking when asking a password.)Ted Zlatanov, Jul 14, 2011
  13. Jeff KingJul 14, 2011
  14. Ted ZlatanovJul 15, 2011
  15. Jeff KingJul 15, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.