From: Patrick Steinhardt <ps@pks.im>
To: graysongordon-gl <graysongordon1@gmail.com>
Cc: git@vger.kernel.org, gitster@pobox.com, peff@peff.net, avarab@gmail.com
Subject: Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
Date: Wed, 23 Sep 2026 14:42:47 +0200 [thread overview]
Message-ID: <arPI8PfvsKUJSypg@pks.im> (raw)
In-Reply-To: <20260915162348.97792-1-ggordon@gitlab.com>
On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote:
> From: Grayson Gordon <graysongordon1@gmail.com>
>
> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the
> OCSP "Certificate Status Request" extension and any stapled response a
> server sends is ignored, including responses that explicitly state the
> certificate has been revoked.
>
> Add an http.sslVerifyStatus boolean that maps to
> CURLOPT_SSL_VERIFYSTATUS. http_options() is already the collect_fn for a
> urlmatch config, so the per-URL form works with no changes:
>
> git config http.https://example.com/.sslVerifyStatus true
>
> Defaults to false/"off". This is due to the nature of the OCSP protocol.
> If enabled, git would expect to receive OCSP stapled responses. If the
> stapled responses were not present, the connection would be blocked as
> the status of the server's certificate could not be verified. This would
> break connections to legitimate services that don't use OCSP as their
> certificate revocation mechanism.
>
> If the backend can't check the staple, curl_easy_setopt() returns
> CURLE_NOT_BUILT_IN. The error message includes curl_easy_strerror()
> along with the option name, so a libcurl built without status
> verification is easy to identify.
Nit: I feel like this paragraph is excessive information, as it doesn't
give the reviewer any additional context over what the code already
states.
> CURLOPT_SSL_VERIFYSTATUS has existed since libcurl 7.41.0, below our
> 7.61.0 floor, so no version guard is needed.
>
> The tests that need no OCSP infrastructure stay in t5551, which t5559
> runs over https. The rest need a certificate authority, a responder to
> answer for it and a server configured to staple, so lib-httpd gains an
> opt-in LIB_HTTPD_OCSP mode and t5585 uses it to check that a "good"
> staple is accepted, a "revoked" one is refused, and that the revoked one
> is ignored when the option is off.
Nit: Likewise, this paragraph doesn't add much value.
Other than that I'm happy with this patch. I'll leave it to you (or
others) to decide whether this requires another reroll to address the
two nits.
Thanks!
Patrick
next prev parent reply other threads:[~2026-09-23 12:43 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 17:02 [PATCH] http: add http.sslVerifyStatus to check stapled OCSP responses graysongordon-gl
2026-08-11 19:28 ` Junio C Hamano
2026-08-11 20:44 ` [PATCH v2] " graysongordon-gl
2026-08-12 6:25 ` Patrick Steinhardt
2026-08-12 15:53 ` Grayson Gordon
2026-08-12 14:17 ` Junio C Hamano
2026-08-12 18:25 ` [PATCH v3] " graysongordon-gl
2026-08-12 21:34 ` Junio C Hamano
2026-08-13 16:06 ` Junio C Hamano
2026-08-17 18:52 ` [PATCH v4] " graysongordon-gl
2026-08-17 19:19 ` Junio C Hamano
2026-08-18 7:50 ` Patrick Steinhardt
2026-08-18 14:51 ` Grayson Gordon
2026-08-19 8:14 ` Patrick Steinhardt
2026-08-18 16:40 ` Junio C Hamano
2026-08-18 19:37 ` [PATCH v5] " graysongordon-gl
2026-08-18 20:12 ` Junio C Hamano
2026-08-18 21:22 ` Grayson Gordon
2026-08-18 21:48 ` [PATCH v6] " graysongordon-gl
2026-08-26 22:01 ` Junio C Hamano
2026-08-28 13:51 ` Grayson Gordon
2026-08-28 17:20 ` Junio C Hamano
2026-08-31 6:56 ` Patrick Steinhardt
2026-08-31 14:16 ` Junio C Hamano
2026-08-31 14:24 ` Patrick Steinhardt
2026-08-31 14:31 ` Junio C Hamano
2026-09-08 12:55 ` Grayson Gordon
2026-09-15 16:23 ` [PATCH v7] " graysongordon-gl
2026-09-16 19:29 ` Junio C Hamano
2026-09-23 12:42 ` Patrick Steinhardt [this message]
2026-09-23 21:43 ` Junio C Hamano
2026-09-23 21:07 ` SZEDER Gábor
2026-09-23 21:47 ` Junio C Hamano
2026-09-24 7:41 ` SZEDER Gábor
2026-09-24 7:59 ` Patrick Steinhardt
2026-09-25 9:28 ` SZEDER Gábor
2026-09-25 16:13 ` Junio C Hamano
2026-09-24 16:22 ` Junio C Hamano
2026-10-07 18:18 ` Junio C Hamano
2026-10-08 4:57 ` Junio C Hamano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arPI8PfvsKUJSypg@pks.im \
--to=ps@pks.im \
--cc=avarab@gmail.com \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=graysongordon1@gmail.com \
--cc=peff@peff.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox