git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 2/2] config: documentation for HTTPS proxy client cert.

From
Jorge A López Silva <jalopezsilva@gmail.com>
Date
Mar 3, 2020, 01:47 UTC
Message-ID
<CAJyLMU8-OUvOoP1hvgu4PC8iO7oynrvo2CW94HL-neu4RcZ=Ew@mail.gmail.com>
In-Reply-To
<xmqqblpjg8mf.fsf@gitster-ct.c.googlers.com>
> Thanks, this should be part of the previous patch, as it was that
> commit, not this one, that adds 4 options ;-)
Haha, yeah, you're right. I'll collapse the commits into a single one.
Show 11 quoted lines
>  I think these files not merely "indicate" but they themselves
> "hold", "contain" and/or "store" the certificate and key.  Perhaps
> more like...
>         The pathname of a file that stores a client certificate to ...
> Also, it is customary to camelCase the configuration variable names.
> As I understand http.proxykey is roughly corresponds to existing
> http.sslKey (the former is for proxy, the latter is for the target
> host), I'd expect these two to be spelled http.proxySSLCert and
> http.proxySSLKey respectively (without omitting "SSL", as that is
> the underlying cURL option name if I am reading the code in 1/2
> correctly).
Good point. Better descriptions and names will be added.
Show 5 quoted lines
> It is possible that the answer to these questions are the same---an
> on-disk password is a bad idea, so we deliberately omit a config
> that gives value to CURLOPT_KEYPASSWD and instead use the credential
> subsystem (see http.c::has_cert_password() and its caller).  If so,
> I think it would be prudent to follow the same pattern if possible?
Excellent point. Will adjust to re-use the same pattern.
On Thu, Feb 27, 2020 at 10:58 AM Junio C Hamano <gitster@pobox.com> wrote:
Show 65 quoted lines
>
> "Jorge Lopez Silva via GitGitGadget" <gitgitgadget@gmail.com>
> writes:
>
> > From: Jorge Lopez Silva <jalopezsilva@gmail.com>
> >
> > The commit adds 4 options, client cert, key, key password and CA info.
> > The CA info can be used to specify a different CA path to validate the
> > HTTPS proxy cert.
> >
> > Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>
> > ---
>
> Thanks, this should be part of the previous patch, as it was that
> commit, not this one, that adds 4 options ;-)
>
> > +http.proxycert::
> > +     File indicating a client certificate to use to authenticate with an HTTPS proxy.
> > +
> > +http.proxykey::
> > +     File indicating a private key to use to authenticate with an HTTPS proxy.
>
> I think these files not merely "indicate" but they themselves
> "hold", "contain" and/or "store" the certificate and key.  Perhaps
> more like...
>
>         The pathname of a file that stores a client certificate to ...
>
> Also, it is customary to camelCase the configuration variable names.
> As I understand http.proxykey is roughly corresponds to existing
> http.sslKey (the former is for proxy, the latter is for the target
> host), I'd expect these two to be spelled http.proxySSLCert and
> http.proxySSLKey respectively (without omitting "SSL", as that is
> the underlying cURL option name if I am reading the code in 1/2
> correctly).
>
> > +http.proxykeypass::
> > +     When communicating to the proxy using TLS (using an HTTPS proxy), use this
> > +     option along `http.proxykey` to indicate a password for the key.
>
> And this would be "http.proxyKeyPasswd" for the same two reasons.
>
> There are a couple of curious things, though:
>
>  * Is it a good idea to use a keyfile that is encrypted, but leave
>    the encryption password on disk in the configuration file to
>    begin with?
>
>  * This teaches our system about PROXY_KEYPASSWD that protects
>    PROXY_SSLKEY, but why isn't there a similar configuration
>    variable for CURLOPT_KEYPASSWD that protects CURLOPT_SSLKEY?
>
> It is possible that the answer to these questions are the same---an
> on-disk password is a bad idea, so we deliberately omit a config
> that gives value to CURLOPT_KEYPASSWD and instead use the credential
> subsystem (see http.c::has_cert_password() and its caller).  If so,
> I think it would be prudent to follow the same pattern if possible?
>
> > +http.proxycainfo::
> > +     File containing the certificates to verify the proxy with when using an HTTPS
> > +     proxy.
> > +
> >  http.emptyAuth::
> >       Attempt authentication without seeking a username or password.  This
> >       can be used to attempt GSS-Negotiate authentication without specifying
Previous: Junio C HamanoNext: Jorge Lopez Silva via GitGitGadget
Message 9 of 15 in “Add HTTPS proxy SSL options (cert, key, cainfo)”
  1. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 21, 2020
  2. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  3. Eric SunshineFeb 21, 2020
  4. Jorge A López SilvaFeb 26, 2020
  5. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  6. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 26, 2020
  7. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  8. Junio C HamanoFeb 27, 2020
  9. Jorge A López SilvaMar 3, 2020
  10. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  11. Junio C HamanoFeb 27, 2020
  12. Jorge A López SilvaMar 3, 2020
  13. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Mar 4, 2020
  14. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020
  15. 2/2 http: add environment variable for HTTPS proxy.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.