* Re: https access to git repo?
[not found] ` <6b35da7f-91bc-92d2-6ea3-71cbe5d3d768@gmail.com>
@ 2018-11-02 14:37 ` Eric Blake
0 siblings, 0 replies; only message in thread
From: Eric Blake @ 2018-11-02 14:37 UTC (permalink / raw)
To: overseers
Forwarding a message from cygwin-developers:
On 11/2/18 9:32 AM, cyg Simple wrote:
> On 11/2/2018 9:20 AM, Eric Blake wrote:
>> https://cygwin.com/git.html recommends the use of git:// for accessing
>> the cygwin git repo. However, git:// suffers from man-in-the-middle
>> attacks, in comparison to https://. On the other hand, performance of
>> https:// is much worse than git:// UNLESS the git server is running a
>> new enough version of git, such that it advertises
>> application/x-git-upload-pack-advertisement support.
>>
>> Alas, the current sourceware server is running an old version of git:
>>
>> $ wget -S
>> 'http://sourceware.org/git/newlib-cygwin.git/info/refs?service=git-upload-pack'
>> 2>&1 | grep Content-Type
>> Â Content-Type: text/plain; charset=UTF-8
>>
>> Contrast that with other git repos:
>>
>> $ wget -S
>> 'https://repo.or.cz/qemu.git/info/refs?service=git-upload-pack' 2>&1 |
>> grep Content-Type
>> Â Content-Type: application/x-git-upload-pack-advertisement
>>
>> Is there a chance we can get sourceware to upgrade to a newer git
>> server, and then update our recommendations to point people to https://
>> clones instead of insecure git://, and without the current speed penalty
>> that current https:// access through our non-upgraded server provides?
>
> You'll need to ask overseerers@sourceware.org. They may have it on
> there radar already but it doesn't hurt to ask.
>
--
Eric Blake, Principal Software Engineer
Red Hat, Inc. +1-919-301-3266
Virtualization: qemu.org | libvirt.org
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2018-11-02 14:37 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <09575e79-a64c-6227-34e3-3bc10290e7a5@redhat.com>
[not found] ` <6b35da7f-91bc-92d2-6ea3-71cbe5d3d768@gmail.com>
2018-11-02 14:37 ` https access to git repo? Eric Blake
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).