git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 1/2] http: add client cert for HTTPS proxies.

From
JGJorge Lopez Silva via GitGitGadget <gitgitgadget@gmail.com>
Date
Feb 26, 2020, 23:23 UTC
Message-ID
<a5d980e7501b1e0ab6f20a97136cd3a58427a139.1582759438.git.gitgitgadget@gmail.com>
In-Reply-To
<pull.559.v2.git.1582759438.gitgitgadget@gmail.com>
From: Jorge Lopez Silva <jalopezsilva@gmail.com>

Git currently supports performing connections to HTTPS proxies but we don't support doing mutual authentication with them (through TLS). This commit adds the necessary options to be able to send a client certificate to the HTTPS proxy.

A client certificate can provide an alternative way of authentication instead of using 'ProxyAuthorization' or other more common methods of authentication.

Libcurl supports this functionality already. The feature is guarded by the first available libcurl version that supports these options.

Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>
---
 http.c | 48 +++++++++++++++++++++++++++++++++++++++++++-----
 1 file changed, 43 insertions(+), 5 deletions(-)
diff --git a/http.c b/http.c
index 00a0e507633..88782d39f15 100644
--- a/http.c
+++ b/http.c
@@ -86,6 +86,14 @@ static long curl_low_speed_time = -1;
 static int curl_ftp_no_epsv;
 static const char *curl_http_proxy;
 static const char *http_proxy_authmethod;
+
+#if LIBCURL_VERSION_NUM >= 0x073400
+static const char *http_proxy_ssl_cert;
+static const char *http_proxy_ssl_key;
+static const char *http_proxy_ssl_keypasswd;
+#endif
+static const char *http_proxy_ssl_ca_info;
+
 static struct {
 	const char *name;
 	long curlauth_param;
@@ -365,6 +373,20 @@ static int http_options(const char *var, const char *value, void *cb)
 	if (!strcmp("http.proxyauthmethod", var))
 		return git_config_string(&http_proxy_authmethod, var, value);
 
+#if LIBCURL_VERSION_NUM >= 0x073400
+	if (!strcmp("http.proxycert", var))
+		return git_config_string(&http_proxy_ssl_cert, var, value);
+
+	if (!strcmp("http.proxykey", var))
+		return git_config_string(&http_proxy_ssl_key, var, value);
+
+	if (!strcmp("http.proxykeypass", var))
+		return git_config_string(&http_proxy_ssl_keypasswd, var, value);
+
+	if (!strcmp("http.proxycainfo", var))
+		return git_config_string(&http_proxy_ssl_ca_info, var, value);
+#endif
+
 	if (!strcmp("http.cookiefile", var))
 		return git_config_pathname(&curl_cookie_file, var, value);
 	if (!strcmp("http.savecookies", var)) {
@@ -924,8 +946,14 @@ static CURL *get_curl_handle(void)
 #if LIBCURL_VERSION_NUM >= 0x073400
 		curl_easy_setopt(result, CURLOPT_PROXY_CAINFO, NULL);
 #endif
-	} else if (ssl_cainfo != NULL)
-		curl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);
+	} else if (ssl_cainfo != NULL || http_proxy_ssl_ca_info != NULL) {
+		if (ssl_cainfo != NULL)
+			curl_easy_setopt(result, CURLOPT_CAINFO, ssl_cainfo);
+#if LIBCURL_VERSION_NUM >= 0x073400
+		if (http_proxy_ssl_ca_info != NULL)
+			curl_easy_setopt(result, CURLOPT_PROXY_CAINFO, http_proxy_ssl_ca_info);
+#endif
+	}
 
 	if (curl_low_speed_limit > 0 && curl_low_speed_time > 0) {
 		curl_easy_setopt(result, CURLOPT_LOW_SPEED_LIMIT,
@@ -1018,9 +1046,19 @@ static CURL *get_curl_handle(void)
 				CURLOPT_PROXYTYPE, CURLPROXY_SOCKS4);
 #endif
 #if LIBCURL_VERSION_NUM >= 0x073400
-		else if (starts_with(curl_http_proxy, "https"))
-			curl_easy_setopt(result,
-				CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);
+		else if (starts_with(curl_http_proxy, "https")) {
+			curl_easy_setopt(result, CURLOPT_PROXYTYPE, CURLPROXY_HTTPS);
+
+			if (http_proxy_ssl_cert != NULL)
+				curl_easy_setopt(result, CURLOPT_PROXY_SSLCERT, http_proxy_ssl_cert);
+
+			if (http_proxy_ssl_key != NULL)
+				curl_easy_setopt(result, CURLOPT_PROXY_SSLKEY, http_proxy_ssl_key);
+
+			if (http_proxy_ssl_keypasswd != NULL)
+				curl_easy_setopt(result, CURLOPT_PROXY_KEYPASSWD, http_proxy_ssl_keypasswd);
+
+		}
 #endif
 		if (strstr(curl_http_proxy, "://"))
 			credential_from_url(&proxy_auth, curl_http_proxy);
-- 
gitgitgadget
Previous: Jorge A López SilvaNext: Junio C Hamano
Message 10 of 15 in “Add HTTPS proxy SSL options (cert, key, cainfo)”
  1. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 21, 2020
  2. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  3. Eric SunshineFeb 21, 2020
  4. Jorge A López SilvaFeb 26, 2020
  5. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  6. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 26, 2020
  7. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  8. Junio C HamanoFeb 27, 2020
  9. Jorge A López SilvaMar 3, 2020
  10. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  11. Junio C HamanoFeb 27, 2020
  12. Jorge A López SilvaMar 3, 2020
  13. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Mar 4, 2020
  14. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020
  15. 2/2 http: add environment variable for HTTPS proxy.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.