Re: Update on git.php.net incident

From: Date: Wed, 07 Apr 2021 16:07:44 +0000
Subject: Re: Update on git.php.net incident
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-113989@lists.php.net to get a copy of this message
Nikita Popov in php.internals (Tue, 6 Apr 2021 20:28:03 +0200):
>Something I was not aware of at the time is that git.php.net
>(intentionally) supported pushing changes not only via SSH (using the
>gitolite infrastructure and public key cryptography), but also via HTTPS.
>The latter did not use gitolite, and instead used git-http-backend behind
>Apache2 Digest authentication against the master.php.net user database. I'm
>not sure why password-based authentication was supported in the first
>place, as it is much less secure than pubkey authentication.

Password-based authentication on Github is deprecated for some time now
and will be disabled on August 13, 2021. See the timeline in
https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/
-- 
Jan


Thread (4 messages)

« previous php.internals (#113989) next »