Fossil SCM

SSL client certificates

Closed

0d1971c5aee58c9… · opened 14 years, 10 months ago

Type
Feature_Request
Priority
Severity
Important
Resolution
Fixed
Subsystem
Created
June 2, 2011 7:27 a.m.

It would be useful to support client certificates for https connections. Making sure that unauthorised requests never invoke the fossil cgi handler gives an extra level of assurance to those who have paranoid tendencies.

I implemented a very simple approach in the ben-security branch (--ssl-identity option to clone, which stores the path to PEM encoded cert and key in the ssl-identity setting), before noticing the jan-clientcert branch which provides a much more comprehensive certificate management feature (certs sub-command, certs table in repo db, client side cert passphrases, plus enhancements to the server certificate checking).

What should I do to get support for client certificates into a state suitable for incorporating into the release version?


ben added on 2011-08-15 09:10:39 UTC: Implemented in [9a0c995826]


Keyboard Shortcuts

Open search /
Next entry (timeline) j
Previous entry (timeline) k
Open focused entry Enter
Show this help ?
Toggle theme Top nav button