git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 1/1] send-email: add client certificate options

From
Junio C Hamano <gitster@pobox.com>
Date
Mar 2, 2026, 16:43 UTC
Message-ID
<xmqq7bru41xz.fsf@gitster.g>
In-Reply-To
<20260302032048.260209-2-dxdt@dev.snart.me>
David Timber <dxdt@dev.snart.me> writes:
Show 32 quoted lines
> For SMTP servers that do "mutual certificate verification", the mail
> client is required to present its own TLS certificate as well. This
> patch adds --smtp-ssl-client-cert and --smtp-ssl-client-key for such
> servers.
>
> The problem of which private key for the certificate is chosen arises
> when there are private keys in both the certificate and private key
> file. According to the documentation of IO::Socket::SSL(link supplied),
> the behaviour(the private key chosen) depends on the format of the
> certificate. In a nutshell,
>
> 	- PKCS12: the key in the cert always takes the precedence
> 	- PEM: if the key file is not given, it will "try" to read one
> 	  from the cert PEM file
>
> Many users may find this discrepancy unintuitive.
>
> In terms of client certificate, git-send-email is implemented in a way
> that what's possible with perl's SSL library is exposed to the user as
> much as possible. In this instance, the user may choose to use a PEM
> file that contains both certificate and private key should be
> at their discretion despite the implications.
>
> Link: https://metacpan.org/pod/IO::Socket::SSL#SSL_cert_file-%7C-SSL_cert-%7C-SSL_key_file-%7C-SSL_key
> Link: https://lore.kernel.org/all/319bf98c-52df-4bf9-b157-e4bc2bf087d6@dev.snart.me/
>
> Signed-off-by: David Timber <dxdt@dev.snart.me>
> ---
>  Documentation/config/sendemail.adoc | 16 ++++++++++
>  Documentation/git-send-email.adoc   | 19 ++++++++++++
>  git-send-email.perl                 | 47 ++++++++++++++++++++++-------
>  3 files changed, 71 insertions(+), 11 deletions(-)
It's a lot of text but quite informative.  Will replace.
Shall we declare victory and mark the topic for 'next' now?
Thanks.
Previous: David TimberNext: David Timber
Message 8 of 10 in “send-email: add client certificate options”
  1. 0/1 send-email: add client certificate optionsDavid Timber, Feb 20, 2026
  2. 1/1 send-mail: add client certificate optionsDavid Timber, Feb 20, 2026
  3. Junio C HamanoFeb 20, 2026
  4. David TimberFeb 21, 2026
  5. Junio C HamanoFeb 26, 2026
  6. 0/1 send-email: add client certificate optionsDavid Timber, Mar 2, 2026
  7. 1/1 send-email: add client certificate optionsDavid Timber, Mar 2, 2026
  8. Junio C HamanoMar 2, 2026
  9. David TimberMar 4, 2026
  10. Junio C HamanoFeb 20, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.