git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 2/2] http.c: add http.sslCertType and http.sslKeyType

From
Mark Lodato <lodatom@gmail.com>
Date
Jun 16, 2009, 00:55 UTC
Message-ID
<ca433830906151755t783fbf98k3fd09e4bdd6781e8@mail.gmail.com>
In-Reply-To
<alpine.OSX.2.00.0906151927010.816@xor.localnet>
On Mon, Jun 15, 2009 at 1:43 PM, Karsten Weiss<knweiss@gmx.de> wrote:
Show 14 quoted lines
> Hi Mark!
>
> On Sun, 14 Jun 2009, Mark Lodato wrote:
>
>> Add two new configuration variables, http.sslCertType and
>> http.sslKeyType, which tell libcurl the filetype for the SSL client
>> certificate and private key, respectively.  The main benefit is to allow
>> PKCS12 certificates for users with libcurl >= 7.13.0.
>
> This is interesting. Thanks for working on that!
>
> (However, it's a similar issue like the question whether the private key is
> encrypted or not: Usability would be better if the certificate type could be
> determined automatically (without having to violate the layering)).

Just as with determining if the certificate is password protected, it is equally difficult to tell what type of file it is without calling OpenSSL directly.

This brings up a good point: Should we (I) try to implement (client certificate) usability features in git to work around deficiencies in libcurl, or should we (I) write patches to fix/enhance libcurl directly? The latter would be much easier (though I could be wrong) and would benefit other programs using libcurl, but would require users to upgrade libcurl to get these new features, and of course would rely on the libcurl developers accepting the patches. I am willing to do either, but I think the libcurl route would be better. Any thoughts?

Anyway, to implement this in git, the algorithm would be something like:
for password in [None, "", prompt()]:
 for type in ["PEM", "DER", (if libcurl >= 7.13.0) "P12"]:
  try to make a connection with password and type
  if not certificate error:
   return success
else:
 return failure

This is much more difficult than it may at first appear. I'm sure it can be done, but it will take a while to get it right.

Mark
Previous: Karsten WeissNext: Junio C Hamano
Message 4 of 11 in “http.c: fix compiling with libcurl 7.9.2”
  1. 1/2 http.c: fix compiling with libcurl 7.9.2Mark Lodato, Jun 15, 2009
  2. 2/2 http.c: add http.sslCertType and http.sslKeyTypeMark Lodato, Jun 15, 2009
  3. Karsten WeissJun 15, 2009
  4. Mark LodatoJun 16, 2009
  5. Junio C HamanoJun 16, 2009
  6. Junio C HamanoJun 16, 2009
  7. Karsten WeissJun 16, 2009
  8. Mark LodatoJun 16, 2009
  9. Junio C HamanoJun 15, 2009
  10. Tay Ray ChuanJun 15, 2009
  11. Mike RalphsonJun 18, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.