Git development
 help / color / mirror / Atom feed
From: Karsten Weiss <knweiss@gmx.de>
To: git@vger.kernel.org
Cc: Mark Lodato <lodatom@gmail.com>
Subject: Re: https, client certificate, pem pass phrase
Date: Thu, 11 Jun 2009 18:43:50 +0200 (CEST)	[thread overview]
Message-ID: <alpine.OSX.2.00.0906111801400.67531@xor.localnet> (raw)
In-Reply-To: <alpine.OSX.2.00.0906110956370.945@xor.localnet>

On Thu, 11 Jun 2009, Karsten Weiss wrote:

> However, it only works as long as I do *not* protect the client's private key 
> (PEM) with a pass phrase which is not secure (especially when using 
> FakeBasicAuth!). When I do protect the private key with a pass phrase *each* 
> git fetch/pull/push prompts the user *several* times with "Enter PEM pass 
> phrase:". Thus, it's not usable (even though it works).

Somehow I managed to miss Mark Lodato's posting from 2009-05-28 before:

[PATCH 1/2] http.c: prompt for SSL client certificate password
http://marc.info/?l=git&m=124348062226665&w=4
[PATCH 2/2] http.c: add http.sslCertNoPass option
http://marc.info/?l=git&m=124348062326671&w=4

I can confirm that his two patches solve the problem. I.e. there is now 
only a single passphrase prompt during each Git invocation that involves 
the https protocol. Great!

However, I want to add two additional suggestions:

With the patch Git prompts for a "Certificate Password". IMHO it would be 
better to prompt for the "Certificate private key passphrase" because it's 
the private key which is protected and not the certificate itself. The 
config flag IMHO also should be renamed from http.sslCertNoPass to 
http.sslKeyNoPassphrase. (Of course it would be even nicer if the code 
could detect if the key has a passphrase and only prompt for it when 
really necessary)

Regarding the caching of the passphrase in memory: Maybe the passphrase 
memory region could be mlock()ed to prevent the kernel from paging it to 
disk? But I'm not sure if this is worth effort.

  reply	other threads:[~2009-06-11 16:45 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-06-11  8:36 https, client certificate, pem pass phrase Karsten Weiss
2009-06-11 16:43 ` Karsten Weiss [this message]
2009-06-11 23:54   ` Mark Lodato

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=alpine.OSX.2.00.0906111801400.67531@xor.localnet \
    --to=knweiss@gmx.de \
    --cc=git@vger.kernel.org \
    --cc=lodatom@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox