{"thread":{"id":"12228","subject":"GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","startedAt":"2008-02-20T23:35:54Z","lastAt":"2008-02-22T10:53:39Z","messageCount":9,"participants":["Anatoly Yakovenko","Mike Hommey","Daniel Stenberg","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"69426","messageId":"e26d18e40802201535s7a5c12fbtd61d2445426f4018@mail.gmail.com","threadId":"12228","inReplyTo":null,"subject":"GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Anatoly Yakovenko","fromEmail":"aeyakovenko@gmail.com","sentAt":"2008-02-20T23:35:54Z","receivedAt":"2008-02-20T23:35:54Z","isPatch":false,"sender":{"key":"aeyakovenko@gmail.com","avatar":"https://gravatar.com/avatar/e9c7bbbeb8dfc45fc901551c15d459b7531e27bce344e15fc8f3aa39c8511a7f?d=mp&s=160"},"body":"I am not sure if its a bug in curl or git, but despite setting\nGIT_SSL_NO_VERIFY=1, if i use a different ip address or hostname then\nthe certificate was signed for, git fails to push changes.\n"},{"id":"69460","messageId":"20080221064252.GA16036@glandium.org","threadId":"12228","inReplyTo":"e26d18e40802201535s7a5c12fbtd61d2445426f4018@mail.gmail.com","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Mike Hommey","fromEmail":"mh@glandium.org","sentAt":"2008-02-21T06:42:52Z","receivedAt":"2008-02-21T06:42:52Z","isPatch":false,"sender":{"key":"mh@glandium.org","avatar":"https://avatars.githubusercontent.com/u/1038527?v=4"},"body":"On Wed, Feb 20, 2008 at 03:35:54PM -0800, Anatoly Yakovenko wrote:\n> I am not sure if its a bug in curl or git, but despite setting\n> GIT_SSL_NO_VERIFY=1, if i use a different ip address or hostname then\n> the certificate was signed for, git fails to push changes.\n\nCan you try with GIT_CURL_VERBOSE=1 ? The trace message will probably\nhelp understanding what happens.\n\nMike\n"},{"id":"69498","messageId":"e26d18e40802211057o255246f3p31800c73eb8391ec@mail.gmail.com","threadId":"12228","inReplyTo":"20080221064252.GA16036@glandium.org","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Anatoly Yakovenko","fromEmail":"aeyakovenko@gmail.com","sentAt":"2008-02-21T18:57:58Z","receivedAt":"2008-02-21T18:57:58Z","isPatch":false,"sender":{"key":"aeyakovenko@gmail.com","avatar":"https://gravatar.com/avatar/e9c7bbbeb8dfc45fc901551c15d459b7531e27bce344e15fc8f3aa39c8511a7f?d=mp&s=160"},"body":"yep, it tells me that the certificate is rejected because it was\nsigned for a different ip then the one i am connected too.  while this\nis a security threat, browsers will let you ignore it, so i expect\nthat libcurl or git should be able to ignore that error as well.\n\nOn Wed, Feb 20, 2008 at 10:42 PM, Mike Hommey <mh@glandium.org> wrote:\n>\n> On Wed, Feb 20, 2008 at 03:35:54PM -0800, Anatoly Yakovenko wrote:\n>  > I am not sure if its a bug in curl or git, but despite setting\n>  > GIT_SSL_NO_VERIFY=1, if i use a different ip address or hostname then\n>  > the certificate was signed for, git fails to push changes.\n>\n>  Can you try with GIT_CURL_VERBOSE=1 ? The trace message will probably\n>  help understanding what happens.\n>\n>  Mike\n>\n"},{"id":"69500","messageId":"Pine.LNX.4.64.0802212003140.14691@yvahk3.pbagnpgbe.fr","threadId":"12228","inReplyTo":"e26d18e40802211057o255246f3p31800c73eb8391ec@mail.gmail.com","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2008-02-21T19:04:11Z","receivedAt":"2008-02-21T19:04:11Z","isPatch":false,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 21 Feb 2008, Anatoly Yakovenko wrote:\n\n> yep, it tells me that the certificate is rejected because it was signed for \n> a different ip then the one i am connected too.  while this is a security \n> threat, browsers will let you ignore it, so i expect that libcurl or git \n> should be able to ignore that error as well.\n\nlibcurl can most certainly be told to ignore that:\n\nhttp://curl.haxx.se/libcurl/c/curl_easy_setopt.html#CURLOPTSSLVERIFYHOST\n"},{"id":"69501","messageId":"20080221190954.GA24759@glandium.org","threadId":"12228","inReplyTo":"e26d18e40802211057o255246f3p31800c73eb8391ec@mail.gmail.com","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Mike Hommey","fromEmail":"mh@glandium.org","sentAt":"2008-02-21T19:09:54Z","receivedAt":"2008-02-21T19:09:54Z","isPatch":false,"sender":{"key":"mh@glandium.org","avatar":"https://avatars.githubusercontent.com/u/1038527?v=4"},"body":"On Thu, Feb 21, 2008 at 10:57:58AM -0800, Anatoly Yakovenko wrote:\n> yep, it tells me that the certificate is rejected because it was\n> signed for a different ip then the one i am connected too.  while this\n> is a security threat, browsers will let you ignore it, so i expect\n> that libcurl or git should be able to ignore that error as well.\n\nWhat is the exact message ?\n\nMike\n"},{"id":"69502","messageId":"1203621790-1415-1-git-send-email-mh@glandium.org","threadId":"12228","inReplyTo":"Pine.LNX.4.64.0802212003140.14691@yvahk3.pbagnpgbe.fr","subject":"[PATCH] Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is set","fromName":"Mike Hommey","fromEmail":"mh@glandium.org","sentAt":"2008-02-21T19:23:10Z","receivedAt":"2008-02-21T19:23:10Z","isPatch":true,"sender":{"key":"mh@glandium.org","avatar":"https://avatars.githubusercontent.com/u/1038527?v=4"},"body":"\nSigned-off-by: Mike Hommey <mh@glandium.org>\n---\n http.c |    1 +\n 1 files changed, 1 insertions(+), 0 deletions(-)\n\ndiff --git a/http.c b/http.c\nindex 5925d07..519621a 100644\n--- a/http.c\n+++ b/http.c\n@@ -177,6 +177,7 @@ static CURL* get_curl_handle(void)\n \tCURL* result = curl_easy_init();\n \n \tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);\n+\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, curl_ssl_verify * 2);\n #if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n #endif\n-- \n1.5.4.1.48.g0d77\n"},{"id":"69533","messageId":"7vd4qpsy6q.fsf@gitster.siamese.dyndns.org","threadId":"12228","inReplyTo":"1203621790-1415-1-git-send-email-mh@glandium.org","subject":"Re: [PATCH] Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is set","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2008-02-21T23:10:37Z","receivedAt":"2008-02-21T23:10:37Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Mike Hommey <mh@glandium.org> writes:\n\n> Signed-off-by: Mike Hommey <mh@glandium.org>\n> ---\n>  http.c |    1 +\n>  1 files changed, 1 insertions(+), 0 deletions(-)\n>\n> diff --git a/http.c b/http.c\n> index 5925d07..519621a 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -177,6 +177,7 @@ static CURL* get_curl_handle(void)\n>  \tCURL* result = curl_easy_init();\n>  \n>  \tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);\n> +\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, curl_ssl_verify * 2);\n>  #if LIBCURL_VERSION_NUM >= 0x070907\n>  \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n>  #endif\n\nIs it just me who finds that \"* 2\" is extremely magical?\n\ndiff --git a/http.c b/http.c\nindex 5925d07..8dce820 100644\n--- a/http.c\n+++ b/http.c\n@@ -176,7 +176,16 @@ static CURL* get_curl_handle(void)\n {\n \tCURL* result = curl_easy_init();\n \n-\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);\n+\tif (!curl_ssl_verify) {\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, 0);\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 0);\n+\t} else {\n+\t\t/* Verify authenticity of the peer's certificate */\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, 1);\n+\t\t/* The name in the cert must match whom we tried to connect */\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);\n+\t}\n+\n #if LIBCURL_VERSION_NUM >= 0x070907\n \tcurl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);\n #endif\n"},{"id":"69545","messageId":"e26d18e40802211727w4f7f5b37vc73a756f6b384289@mail.gmail.com","threadId":"12228","inReplyTo":"20080221190954.GA24759@glandium.org","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Anatoly Yakovenko","fromEmail":"aeyakovenko@gmail.com","sentAt":"2008-02-22T01:27:20Z","receivedAt":"2008-02-22T01:27:20Z","isPatch":false,"sender":{"key":"aeyakovenko@gmail.com","avatar":"https://gravatar.com/avatar/e9c7bbbeb8dfc45fc901551c15d459b7531e27bce344e15fc8f3aa39c8511a7f?d=mp&s=160"},"body":"On Thu, Feb 21, 2008 at 11:09 AM, Mike Hommey <mh@glandium.org> wrote:\n> On Thu, Feb 21, 2008 at 10:57:58AM -0800, Anatoly Yakovenko wrote:\n>  > yep, it tells me that the certificate is rejected because it was\n>  > signed for a different ip then the one i am connected too.  while this\n>  > is a security threat, browsers will let you ignore it, so i expect\n>  > that libcurl or git should be able to ignore that error as well.\n>\n>  What is the exact message ?\n\n$ GIT_SSL_NO_VERIFY=1 GIT_CURL_VERBOSE=1 git clone\nhttps://aeyakovenko@127.0.0.1/git\n\ni get this as an error:\n\nerror: SSL: certificate subject name 'localhost' does not match target\nhost name '127.0.0.1' (curl_result = 51, http_code = 0, sha1 =\n4590de71622f1a90f906413fd7f63d5553cd5f93)\n\ncloning https://aeyakovenko@localhost/git works fine\n"},{"id":"69573","messageId":"Pine.LNX.4.64.0802221149210.13958@yvahk3.pbagnpgbe.fr","threadId":"12228","inReplyTo":"e26d18e40802211727w4f7f5b37vc73a756f6b384289@mail.gmail.com","subject":"Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2008-02-22T10:53:39Z","receivedAt":"2008-02-22T10:53:39Z","isPatch":false,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Thu, 21 Feb 2008, Anatoly Yakovenko wrote:\n\n> $ GIT_SSL_NO_VERIFY=1 GIT_CURL_VERBOSE=1 git clone\n> https://aeyakovenko@127.0.0.1/git\n>\n> i get this as an error:\n>\n> error: SSL: certificate subject name 'localhost' does not match target\n> host name '127.0.0.1' (curl_result = 51, http_code = 0, sha1 =\n> 4590de71622f1a90f906413fd7f63d5553cd5f93)\n\nThat's the very problem Mike Hommey's recent patch addresses. Verifying a \npeer's certificate is done with two different libcurl options:\n\n* VERIFYPEER verifies the server's certificate against a local CA cert bundle\n\n* VERIFYHOST verifies that the name in the server certificate matches the host\n   you're talking to\n\nFor this particular case, you can in fact also make it work by making sure the \nserver's certificate has the IP address as a \"subjectAltName\".\n"}]}