git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: https, client certificate, pem pass phrase

From
KWKarsten Weiss <knweiss@gmx.de>
Date
Jun 11, 2009, 16:43 UTC
Message-ID
<alpine.OSX.2.00.0906111801400.67531@xor.localnet>
In-Reply-To
<alpine.OSX.2.00.0906110956370.945@xor.localnet>
On Thu, 11 Jun 2009, Karsten Weiss wrote:
Show 5 quoted lines
> However, it only works as long as I do *not* protect the client's private key 
> (PEM) with a pass phrase which is not secure (especially when using 
> FakeBasicAuth!). When I do protect the private key with a pass phrase *each* 
> git fetch/pull/push prompts the user *several* times with "Enter PEM pass 
> phrase:". Thus, it's not usable (even though it works).
Somehow I managed to miss Mark Lodato's posting from 2009-05-28 before:

[PATCH 1/2] http.c: prompt for SSL client certificate password http://marc.info/?l=git&m=124348062226665&w=4 [PATCH 2/2] http.c: add http.sslCertNoPass option http://marc.info/?l=git&m=124348062326671&w=4

I can confirm that his two patches solve the problem. I.e. there is now only a single passphrase prompt during each Git invocation that involves the https protocol. Great!

However, I want to add two additional suggestions:

With the patch Git prompts for a "Certificate Password". IMHO it would be better to prompt for the "Certificate private key passphrase" because it's the private key which is protected and not the certificate itself. The config flag IMHO also should be renamed from http.sslCertNoPass to http.sslKeyNoPassphrase. (Of course it would be even nicer if the code could detect if the key has a passphrase and only prompt for it when really necessary)

Regarding the caching of the passphrase in memory: Maybe the passphrase memory region could be mlock()ed to prevent the kernel from paging it to disk? But I'm not sure if this is worth effort.

Previous: Karsten WeissNext: Mark Lodato
Message 2 of 3 in “https, client certificate, pem pass phrase”
  1. Karsten WeissJun 11, 2009
  2. Karsten WeissJun 11, 2009
  3. Mark LodatoJun 11, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.