# Can't get git clone over https with proxy and invalid certificate...

3 messages from 2008-08-08 to 2008-08-08. Participants: Giovanni Funchal, Shawn O. Pearce.
Thread: https://gitlist.dev/t/14888

## Giovanni Funchal, 2008-08-08 11:48

Subject: Can't get git clone over https with proxy and invalid certificate...
Message-ID: <c475e2e60808080448x40683db1wadcd834e94d7d263@mail.gmail.com>
URL: https://gitlist.dev/e/c475e2e60808080448x40683db1wadcd834e94d7d263%40mail.gmail.com

```
Hi all,

I've been trying without success to clone a git repository over https.
I've got a complicated situation because I have a proxy which only
allows http/https and the server I'm trying to connect to has an
invalid certificate. I'm using git 1.5.6.4 and curl 7.18.1 compiled on
x86_64.

Ok, so I have created the following ~/.curlrc:
   netrc
   proxytunnel
   insecure
   proxy = http://proxyserver.com:8080
   proxy-user = proxyuser:proxypassword

accompanied by the following ~/.netrc:
   machine remoteserver.com
   login remoteuser
   password remotepassword

and the following ~/.gitconfig:
   [user]
      name = My Name
      email = my.em@il.com
   [http]
      sslVerify = false

All above files permissions are set to 600 and I have also set the
environment variables http_proxy, https_proxy and all_proxy (one never
knows) to:
   http://proxyuser:proxypassword@proxyserver.com:8080

Ok, now lets try:

$ wget -q --no-check-certificate
https://remoteuser@remoteserver.com/.git/HEAD && cat HEAD && rm HEAD
ref: refs/heads/master
$ curl https://remoteuser@remoteserver.com/.git/HEAD
ref: refs/heads/master
$ git clone https://remoteuser@remoteserver.com/.git/
Initialized empty Git repository in /home/user/.git/
error: Proxy requires authorization!
warning: remote HEAD refers to nonexistent ref, unable to checkout.

Both wget and curl work, but git won't! Any clues?

Thanks in advance and best regards,
-- Giovanni

```

## Shawn O. Pearce, 2008-08-08 14:28

Subject: Re: Can't get git clone over https with proxy and invalid certificate...
Message-ID: <20080808142819.GJ28749@spearce.org>
URL: https://gitlist.dev/e/20080808142819.GJ28749%40spearce.org
In-Reply-To: <c475e2e60808080448x40683db1wadcd834e94d7d263@mail.gmail.com>

```
Giovanni Funchal <gafunchal@gmail.com> wrote:
> Ok, so I have created the following ~/.curlrc:
>    netrc
>    proxytunnel
>    insecure
>    proxy = http://proxyserver.com:8080
>    proxy-user = proxyuser:proxypassword
...
> $ git clone https://remoteuser@remoteserver.com/.git/
> Initialized empty Git repository in /home/user/.git/
> error: Proxy requires authorization!
> warning: remote HEAD refers to nonexistent ref, unable to checkout.

Last time I used Git with an HTTP proxy that required authentication
I was doing it with an environment variable:

  http_proxy=http://me:pass@proxyserver.com:8080 git clone ...

Fortunately this was on a Windows desktop where I was the only
user who was logged into the system, so leaking my password into my
environment for a short duration was about the same risk as putting
into a ~/. file.

-- 
Shawn.

```

## Giovanni Funchal, 2008-08-08 15:13

Subject: Re: Can't get git clone over https with proxy and invalid certificate...
Message-ID: <c475e2e60808080813o4498fc1eu1a08ae05218cec83@mail.gmail.com>
URL: https://gitlist.dev/e/c475e2e60808080813o4498fc1eu1a08ae05218cec83%40mail.gmail.com
In-Reply-To: <20080808142819.GJ28749@spearce.org>

```
Hello,

Well, turns out that my problem was that my gcc doesn't like the `-R'
switch!! Strangely enough, ./configure does not check this!! (one
should define Makefile's existing option NO_R_TO_GCC_LINKER)

While this seems pretty serious, gcc only shows a tiny message while
compiling ("unrecognized option -R"), not even a warning, and compiles
anyway. So if you "make all install doc install-doc" like me, you
won't see the bug.

I think git build system could be improved somehow to check for that.
I'll perhaps try to make a patch to this during the weekend.

Regards,
-- Giovanni

On Fri, Aug 8, 2008 at 4:28 PM, Shawn O. Pearce <spearce@spearce.org> wrote:
> Giovanni Funchal <gafunchal@gmail.com> wrote:
>> Ok, so I have created the following ~/.curlrc:
>>    netrc
>>    proxytunnel
>>    insecure
>>    proxy = http://proxyserver.com:8080
>>    proxy-user = proxyuser:proxypassword
> ...
>> $ git clone https://remoteuser@remoteserver.com/.git/
>> Initialized empty Git repository in /home/user/.git/
>> error: Proxy requires authorization!
>> warning: remote HEAD refers to nonexistent ref, unable to checkout.
>
> Last time I used Git with an HTTP proxy that required authentication
> I was doing it with an environment variable:
>
>  http_proxy=http://me:pass@proxyserver.com:8080 git clone ...
>
> Fortunately this was on a Windows desktop where I was the only
> user who was logged into the system, so leaking my password into my
> environment for a short duration was about the same risk as putting
> into a ~/. file.
>
> --
> Shawn.
>

```
