git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] http: store credential when PKI auth is used

From
Jeff King <peff@peff.net>
Date
Mar 12, 2021, 01:24 UTC
Message-ID
<YErC1LIaxomLd3Gu@coredump.intra.peff.net>
In-Reply-To
<CAEBDL5U=BxHzYWmG2Cpw+XcMJTF8_Qp0KXoKz6N+fHp1ZWdbRQ@mail.gmail.com>
On Thu, Mar 11, 2021 at 08:01:53PM -0500, John Szakmeister wrote:
Show 7 quoted lines
> >   - I think proxy_cert_auth would probably want the same treatment.
> 
> Oh, I think I misread this before making my fixes.  I think what you're
> saying here is that proxy_cert_auth should be approved and rejected
> in the same spots as the client cert auth?  I missed that but am happy
> to add it, if that's what you meant.  The only trouble is that I don't have
> a great way of checking that particular feature.

Yep, that's what I meant. Looking at CURLE_SSL_* in curl.h, it looks like there's no way to distinguish a proxy cert problem from a regular cert problem. So probably we'd need to reject both when we see CURLE_SSL_CERTPROBLEM. As long as somebody is not using both at once, it would not matter at all. And even if they are, the worst case is having to put in their password again.

That said, given that nobody has asked for it and you have no easy way of testing it, I'm content to leave it be for now. Your patches shouldn't make anything worse there, and it shouldn't be too hard to find this discussion in the list archive later.

-Peff
Previous: John Szakmeister
Message 4 of 4 in “http: store credential when PKI auth is used”
  1. http: store credential when PKI auth is usedJohn Szakmeister, Mar 6, 2021
  2. Jeff KingMar 10, 2021
  3. John SzakmeisterMar 12, 2021
  4. Jeff KingMar 12, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.