git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 1/2] http.c: prompt for SSL client certificate password

From
Jakub Narebski <jnareb@gmail.com>
Date
Jun 12, 2009, 16:50 UTC
Message-ID
<m3vdn12y6y.fsf@localhost.localdomain>
In-Reply-To
<85647ef50906120838s37c186a9mec301e880b1a8a4e@mail.gmail.com>
Constantine Plotnikov <constantine.plotnikov@gmail.com> writes:
Show 17 quoted lines
> On Fri, Jun 12, 2009 at 11:56 AM, Daniel Stenberg<daniel@haxx.se> wrote:
>> On Fri, 12 Jun 2009, Nanako Shiraishi wrote:
>>
>>> It would be ideal if you can inspect the certificate and decide if you
>>> need to ask for decrypting password before using it (and otherwise you don't
>>> ask). If you can't do that, probably you can introduce a config var that
>>> says "this certificate is encrypted", and bypass your new code if that
>>> config var isn't set.
>>
>> Is this really a common setup? Using an unencrypted private key sounds like
>> a really bad security situation to me. The certificate is never encrupted,
>> the passphrase is for the key.
>>
> For SSH using unencrypted private key is very common for scripting and
> cron jobs. For HTTPS situation looks like being worse since there is
> no analog of ssh-agent that covers at least some of scripting
> scenarios. Do we want to disable scripting for HTTPS?

Actually you can use _encrypted_ private keys together with ssh-agent and for example keychain helper for scripting. You have to provide password to all listed private keys only once at login. I wonder if something like this would be possible for HTTP certificates...

-- 
Jakub Narebski
Poland
ShadeHawk on #git
Previous: Constantine PlotnikovNext: Rogan Dawes
Message 11 of 25 in “http.c: prompt for SSL client certificate password”
  1. 1/2 http.c: prompt for SSL client certificate passwordMark Lodato, May 28, 2009
  2. 2/2 http.c: add http.sslCertNoPass optionMark Lodato, May 28, 2009
  3. Mark LodatoJun 5, 2009
  4. Constantine PlotnikovJun 5, 2009
  5. Mark LodatoJun 7, 2009
  6. Mark LodatoJun 11, 2009
  7. Nanako ShiraishiJun 11, 2009
  8. Junio C HamanoJun 11, 2009
  9. Daniel StenbergJun 12, 2009
  10. Constantine PlotnikovJun 12, 2009
  11. Jakub NarebskiJun 12, 2009
  12. Rogan DawesJun 12, 2009
  13. Mark LodatoJun 12, 2009
  14. Mark LodatoJun 12, 2009
  15. Junio C HamanoJun 13, 2009
  16. Mark LodatoJun 13, 2009
  17. Daniel StenbergJun 13, 2009
  18. Junio C HamanoJun 11, 2009
  19. Mark LodatoJun 12, 2009
  20. Junio C HamanoJun 12, 2009
  21. Daniel StenbergJun 12, 2009
  22. Mark LodatoJun 12, 2009
  23. Junio C HamanoJun 13, 2009
  24. Mark LodatoJun 13, 2009
  25. Junio C HamanoJun 13, 2009

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.