git/list[1] front-page[2] threads[3] people[4] search[5] about
 

https, client certificate, pem pass phrase

From
KWKarsten Weiss <knweiss@gmx.de>
Date
Jun 11, 2009, 08:36 UTC
Message-ID
<alpine.OSX.2.00.0906110956370.945@xor.localnet>
Hi,

I'm using git-1.6.3.2 (with curl-7.19.5) and would like to configure a private git server to be used over https with client-side certificate and BasicAuth authentication because I want to restrict access to selective and authenticated clients from the Internet which connect to the server through a firewall and web proxy.

So far my test setup works fine. Using SSL FakeBasicAuth I can even access the git server without storing the BasicAuth password unencrypted in ~/.netrc (and there are also no git password prompts).

However, it only works as long as I do *not* protect the client's private key (PEM) with a pass phrase which is not secure (especially when using FakeBasicAuth!). When I do protect the private key with a pass phrase *each* git fetch/pull/push prompts the user *several* times with "Enter PEM pass phrase:". Thus, it's not usable (even though it works).

Is there any way I can prevent this? Ideally, I want to be prompted for the PEM pass phrase once and only once for each git command which uses a secure network connection.

Searching the git mailing list archive I found this thread from February 09 which seems to indicate

git with https and client cert asks for password repeatedly http://marc.info/?l=git&m=123553151323420&w=2

that this really does not work with git's current http code. Can anyone confirm that this is still the case? I'm willing to test patches if somebody is working on this problem.

-- 
Karsten Weiss
Next: Karsten Weiss
Message 1 of 3 in “https, client certificate, pem pass phrase”
  1. Karsten WeissJun 11, 2009
  2. Karsten WeissJun 11, 2009
  3. Mark LodatoJun 11, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.