docs: indicate http.sslCertType and sslKeyType

0a01d41ee4 (http: add support for different sslcert and sslkey types., 2023-03-20) added useful SSL config options, but did not document them. Signed-off-by: Andrew Carter <andrew@emailcarter.com> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Andrew Carter committed Feb 4, 2025 at 23:38 UTC 3eeed876a909c45695f2f3a3edd4141be331a3be
1 file changed +15
Documentation/config/http.txt
+15
@@ -216,6 +216,21 @@ http.sslBackend::
216 This option is ignored if cURL lacks support for choosing the SSL
217 backend at runtime.
218
219 +http.sslCertType::
220 + Type of client certificate used when fetching or pushing over HTTPS.
221 + "PEM", "DER" are supported when using openssl or gnutls backends. "P12"
222 + is supported on "openssl", "schannel", "securetransport", and gnutls 8.11+.
223 + See also libcurl `CURLOPT_SSLCERTTYPE`. Can be overridden by the
224 + `GIT_SSL_CERT_TYPE` environment variable.
225 +
226 +http.sslKeyType::
227 + Type of client private key used when fetching or pushing over HTTPS. (e.g.
228 + "PEM", "DER", or "ENG"). Only applicable when using "openssl" backend. "DER"
229 + is not supported with openssl. Particularly useful when set to "ENG" for
230 + authenticating with PKCS#11 tokens, with a PKCS#11 URL in sslCert option.
231 + See also libcurl `CURLOPT_SSLKEYTYPE`. Can be overridden by the
232 + `GIT_SSL_KEY_TYPE` environment variable.
233 +
234 http.schannelCheckRevoke::
235 Used to enforce or disable certificate revocation checks in cURL
236 when http.sslBackend is set to "schannel". Defaults to `true` if