From: Karsten Weiss <knweiss@gmx.de>
To: git@vger.kernel.org
Subject: https, client certificate, pem pass phrase
Date: Thu, 11 Jun 2009 10:36:14 +0200 (CEST) [thread overview]
Message-ID: <alpine.OSX.2.00.0906110956370.945@xor.localnet> (raw)
Hi,
I'm using git-1.6.3.2 (with curl-7.19.5) and would like to configure a
private git server to be used over https with client-side certificate and
BasicAuth authentication because I want to restrict access to selective
and authenticated clients from the Internet which connect to the server
through a firewall and web proxy.
So far my test setup works fine. Using SSL FakeBasicAuth I can even access
the git server without storing the BasicAuth password unencrypted in
~/.netrc (and there are also no git password prompts).
However, it only works as long as I do *not* protect the client's private
key (PEM) with a pass phrase which is not secure (especially when using
FakeBasicAuth!). When I do protect the private key with a pass phrase
*each* git fetch/pull/push prompts the user *several* times with "Enter
PEM pass phrase:". Thus, it's not usable (even though it works).
Is there any way I can prevent this? Ideally, I want to be prompted for
the PEM pass phrase once and only once for each git command which uses a
secure network connection.
Searching the git mailing list archive I found this thread from February
09 which seems to indicate
git with https and client cert asks for password repeatedly
http://marc.info/?l=git&m=123553151323420&w=2
that this really does not work with git's current http code. Can anyone
confirm that this is still the case? I'm willing to test patches if
somebody is working on this problem.
--
Karsten Weiss
next reply other threads:[~2009-06-11 8:37 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-06-11 8:36 Karsten Weiss [this message]
2009-06-11 16:43 ` https, client certificate, pem pass phrase Karsten Weiss
2009-06-11 23:54 ` Mark Lodato
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=alpine.OSX.2.00.0906110956370.945@xor.localnet \
--to=knweiss@gmx.de \
--cc=git@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox