From: Junio C Hamano Date: Mon, 02 Mar 2026 16:43:20 GMT Subject: Re: [PATCH v2 1/1] send-email: add client certificate options Message-ID: In-Reply-To: <20260302032048.260209-2-dxdt@dev.snart.me> David Timber writes: > For SMTP servers that do "mutual certificate verification", the mail > client is required to present its own TLS certificate as well. This > patch adds --smtp-ssl-client-cert and --smtp-ssl-client-key for such > servers. > > The problem of which private key for the certificate is chosen arises > when there are private keys in both the certificate and private key > file. According to the documentation of IO::Socket::SSL(link supplied), > the behaviour(the private key chosen) depends on the format of the > certificate. In a nutshell, > > - PKCS12: the key in the cert always takes the precedence > - PEM: if the key file is not given, it will "try" to read one > from the cert PEM file > > Many users may find this discrepancy unintuitive. > > In terms of client certificate, git-send-email is implemented in a way > that what's possible with perl's SSL library is exposed to the user as > much as possible. In this instance, the user may choose to use a PEM > file that contains both certificate and private key should be > at their discretion despite the implications. > > Link: https://metacpan.org/pod/IO::Socket::SSL#SSL_cert_file-%7C-SSL_cert-%7C-SSL_key_file-%7C-SSL_key > Link: https://lore.kernel.org/all/319bf98c-52df-4bf9-b157-e4bc2bf087d6@dev.snart.me/ > > Signed-off-by: David Timber > --- > Documentation/config/sendemail.adoc | 16 ++++++++++ > Documentation/git-send-email.adoc | 19 ++++++++++++ > git-send-email.perl | 47 ++++++++++++++++++++++------- > 3 files changed, 71 insertions(+), 11 deletions(-) It's a lot of text but quite informative. Will replace. Shall we declare victory and mark the topic for 'next' now? Thanks.