From: Junio C Hamano <gitster@pobox.com>
To: John Keeping <john@keeping.me.uk>
Cc: "brian m. carlson" <sandals@crustytoothpaste.net>,
Ramkumar Ramachandra <artagnon@gmail.com>,
Git List <git@vger.kernel.org>
Subject: Re: [PATCH v2 2/2] send-email: introduce sendemail.smtpsslcertpath
Date: Fri, 05 Jul 2013 23:25:36 -0700 [thread overview]
Message-ID: <7v1u7c6w7z.fsf@alter.siamese.dyndns.org> (raw)
In-Reply-To: <20130705184333.GN9161@serenity.lan> (John Keeping's message of "Fri, 5 Jul 2013 19:43:33 +0100")
John Keeping <john@keeping.me.uk> writes:
> I'd rather have '$smtp_ssl_cert_path ne ""' in the first if condition
> (instead of the '-d $smtp_ssl_cert_path') ...
I agree. The signal for "no certs" should be an explicit "nonsense"
value like an empty string, not just a string that does not name an
expected filesystem object. Otherwise people can misspell paths and
disable the validation by accident.
> Perhaps a complete solution could allow CA files as well.
Yes, that would be a good idea. Care to roll into a "fixup!" patch
against [2/2]?
> if (defined $smtp_ssl_cert_path) {
> if ($smtp_ssl_cert_path eq "") {
> return (SSL_verify_mode => SSL_VERIFY_NONE);
> } elsif (-f $smtp_ssl_cert_path) {
> return (SSL_verify_mode => SSL_VERIFY_PEER,
> SSL_ca_file => $smtp_ssl_cert_path);
> } else {
> return (SSL_verify_mode => SSL_VERIFY_PEER,
> SSL_ca_path => $smtp_ssl_cert_path);
> }
> } else {
> return (SSL_verify_mode => SSL_VERIFY_PEER);
> }
Two things that worry me a bit are:
(1) At the end user UI level, it may look nice to accept some form
of --no-option-name to say "I have been using SSL against my
server with handrolled cert, and I want to keep using the
verify-none option"; "--ssl-cert-path=" looks somewhat ugly.
The same goes for [sendemail] ssl_cert_path = "" config.
(2) How loudly does the new code barf when no configuration is done
(i.e. we just pass SSL_VERIFY_PEER and let the system default
CA path to take effect) and the server cert does not validate?
The warning that triggered this thread, if we had the
configuration mechanism we have been designing together, would
have been a good reminder for the user to use it, but would we
give a similar (less noisy is fine, as long as it is clear)
diagnostic message?
next prev parent reply other threads:[~2013-07-06 6:25 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-07-05 12:05 [PATCH v2 0/2] Squelch warning from send-email Ramkumar Ramachandra
2013-07-05 12:05 ` [PATCH v2 1/2] send-email: squelch warning from Net::SMTP::SSL Ramkumar Ramachandra
2013-07-06 14:28 ` Torsten Bögershausen
2013-07-06 14:32 ` brian m. carlson
2013-07-06 15:49 ` Torsten Bögershausen
2013-07-14 13:49 ` Ramkumar Ramachandra
2013-07-14 17:03 ` brian m. carlson
2013-07-14 21:49 ` Ramkumar Ramachandra
2013-07-15 3:07 ` Torsten Bögershausen
2013-07-15 4:15 ` Junio C Hamano
2013-07-16 0:15 ` [PATCH] send-email: improve SSL certificate verification brian m. carlson
2013-07-16 2:33 ` Torsten Bögershausen
2013-07-16 2:35 ` brian m. carlson
2013-07-18 16:53 ` Re* " Junio C Hamano
2013-07-18 17:36 ` Ramkumar Ramachandra
2013-07-05 12:05 ` [PATCH v2 2/2] send-email: introduce sendemail.smtpsslcertpath Ramkumar Ramachandra
2013-07-05 12:33 ` Eric Sunshine
2013-07-05 12:36 ` Ramkumar Ramachandra
2013-07-05 12:45 ` brian m. carlson
2013-07-05 12:53 ` Ramkumar Ramachandra
2013-07-05 13:01 ` brian m. carlson
2013-07-05 17:20 ` Junio C Hamano
2013-07-05 17:47 ` John Keeping
2013-07-05 18:30 ` Junio C Hamano
2013-07-05 18:43 ` John Keeping
2013-07-06 6:25 ` Junio C Hamano [this message]
2013-07-06 11:46 ` John Keeping
2013-07-07 4:12 ` Junio C Hamano
2013-07-07 9:02 ` John Keeping
2013-07-05 20:29 ` brian m. carlson
2013-07-07 5:54 ` Jeff King
2013-07-07 10:01 ` Junio C Hamano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: http://vger.kernel.org/majordomo-info.html
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=7v1u7c6w7z.fsf@alter.siamese.dyndns.org \
--to=gitster@pobox.com \
--cc=artagnon@gmail.com \
--cc=git@vger.kernel.org \
--cc=john@keeping.me.uk \
--cc=sandals@crustytoothpaste.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://80x24.org/mirrors/git.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).