git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v2 2/2] config: documentation for HTTPS proxy client cert.

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 27, 2020, 18:58 UTC
Message-ID
<xmqqblpjg8mf.fsf@gitster-ct.c.googlers.com>
In-Reply-To
<c40207a3928f9cbc490b9ef2e99e7cba7788e7c0.1582759438.git.gitgitgadget@gmail.com>

"Jorge Lopez Silva via GitGitGadget" <gitgitgadget@gmail.com> writes:

Show 8 quoted lines
> From: Jorge Lopez Silva <jalopezsilva@gmail.com>
>
> The commit adds 4 options, client cert, key, key password and CA info.
> The CA info can be used to specify a different CA path to validate the
> HTTPS proxy cert.
>
> Signed-off-by: Jorge Lopez Silva <jalopezsilva@gmail.com>
> ---

Thanks, this should be part of the previous patch, as it was that commit, not this one, that adds 4 options ;-)

Show 5 quoted lines
> +http.proxycert::
> +	File indicating a client certificate to use to authenticate with an HTTPS proxy.
> +
> +http.proxykey::
> +	File indicating a private key to use to authenticate with an HTTPS proxy.

I think these files not merely "indicate" but they themselves "hold", "contain" and/or "store" the certificate and key. Perhaps more like...

	The pathname of a file that stores a client certificate to ...

Also, it is customary to camelCase the configuration variable names. As I understand http.proxykey is roughly corresponds to existing http.sslKey (the former is for proxy, the latter is for the target host), I'd expect these two to be spelled http.proxySSLCert and http.proxySSLKey respectively (without omitting "SSL", as that is the underlying cURL option name if I am reading the code in 1/2 correctly).

> +http.proxykeypass::
> +	When communicating to the proxy using TLS (using an HTTPS proxy), use this
> +	option along `http.proxykey` to indicate a password for the key.
And this would be "http.proxyKeyPasswd" for the same two reasons.
There are a couple of curious things, though:
 * Is it a good idea to use a keyfile that is encrypted, but leave
   the encryption password on disk in the configuration file to
   begin with?
 * This teaches our system about PROXY_KEYPASSWD that protects
   PROXY_SSLKEY, but why isn't there a similar configuration
   variable for CURLOPT_KEYPASSWD that protects CURLOPT_SSLKEY?

It is possible that the answer to these questions are the same---an on-disk password is a bad idea, so we deliberately omit a config that gives value to CURLOPT_KEYPASSWD and instead use the credential subsystem (see http.c::has_cert_password() and its caller). If so, I think it would be prudent to follow the same pattern if possible?

Show 7 quoted lines
> +http.proxycainfo::
> +	File containing the certificates to verify the proxy with when using an HTTPS
> +	proxy.
> +
>  http.emptyAuth::
>  	Attempt authentication without seeking a username or password.  This
>  	can be used to attempt GSS-Negotiate authentication without specifying
Previous: Jorge Lopez Silva via GitGitGadgetNext: Jorge A López Silva
Message 8 of 15 in “Add HTTPS proxy SSL options (cert, key, cainfo)”
  1. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 21, 2020
  2. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  3. Eric SunshineFeb 21, 2020
  4. Jorge A López SilvaFeb 26, 2020
  5. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 21, 2020
  6. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Feb 26, 2020
  7. 2/2 config: documentation for HTTPS proxy client cert.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  8. Junio C HamanoFeb 27, 2020
  9. Jorge A López SilvaMar 3, 2020
  10. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Feb 26, 2020
  11. Junio C HamanoFeb 27, 2020
  12. Jorge A López SilvaMar 3, 2020
  13. 0/2 Add HTTPS proxy SSL options (cert, key, cainfo)Jorge via GitGitGadget, Mar 4, 2020
  14. 1/2 http: add client cert for HTTPS proxies.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020
  15. 2/2 http: add environment variable for HTTPS proxy.Jorge Lopez Silva via GitGitGadget, Mar 4, 2020

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.