git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] http, imap-send: stop using CURLOPT_VERBOSE

From
Daniel Stenberg <daniel@haxx.se>
Date
May 13, 2020, 06:16 UTC
Message-ID
<alpine.DEB.2.20.2005130812500.28445@tvnag.unkk.fr>
In-Reply-To
<20200512231331.GA6605@camp.crustytoothpaste.net>
On Tue, 12 May 2020, brian m. carlson wrote:

Sorry for going slightly off-topic, but I figure this could help as a sort of PSA.

> Since everyone uses HTTPS, it's not possible to perform this debugging using 
> a tool like Wireshark unless you use a MITM CA cert, which seems excessive.

When you want to Wireshark the connection with libcurl, your friend is SSLKEYLOGFILE. If you set that environment variable (assuming the libcurl TLS backend supports it - several do), libcurl will save the TLS secrets in the file that environment variable mentions - at run-time in a format that Wireshark understands.

Then you can analyze the traffic, in real time, with Wirehark without fiddling with a MITM etc.

-- 
  / daniel.haxx.se
Previous: Junio C HamanoNext: Jeff King
Message 12 of 21 in “Safer GIT_CURL_VERBOSE”
  1. 0/2 Safer GIT_CURL_VERBOSEJonathan Tan, May 11, 2020
  2. 1/2 t5551: test that GIT_TRACE_CURL redacts passwordJonathan Tan, May 11, 2020
  3. Jeff KingMay 12, 2020
  4. 2/2 http, imap-send: stop using CURLOPT_VERBOSEJonathan Tan, May 11, 2020
  5. Jeff KingMay 12, 2020
  6. Jonathan TanMay 12, 2020
  7. Jeff KingMay 12, 2020
  8. brian m. carlsonMay 12, 2020
  9. Junio C HamanoMay 13, 2020
  10. Jeff KingMay 13, 2020
  11. Junio C HamanoMay 13, 2020
  12. Daniel StenbergMay 13, 2020
  13. Jeff KingMay 13, 2020
  14. 0/3 Safer GIT_CURL_VERBOSEJonathan Tan, May 13, 2020
  15. 2/3 http: make GIT_TRACE_CURL auth redaction optionalJonathan Tan, May 13, 2020
  16. Junio C HamanoMay 13, 2020
  17. 1/3 t5551: test that GIT_TRACE_CURL redacts passwordJonathan Tan, May 13, 2020
  18. 3/3 http, imap-send: stop using CURLOPT_VERBOSEJonathan Tan, May 13, 2020
  19. Junio C HamanoMay 13, 2020
  20. Junio C HamanoMay 13, 2020
  21. Jeff KingMay 15, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.