{"thread":{"id":"29726","subject":"git and SSL certificates","startedAt":"2012-02-24T19:11:27Z","lastAt":"2012-02-24T20:01:42Z","messageCount":3,"participants":["Edward Ned Harvey","Shawn Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"185343","messageId":"000501ccf328$1efe1070$5cfa3150$@nedharvey.com","threadId":"29726","inReplyTo":null,"subject":"git and SSL certificates","fromName":"Edward Ned Harvey","fromEmail":"git@nedharvey.com","sentAt":"2012-02-24T19:11:27Z","receivedAt":"2012-02-24T19:11:27Z","isPatch":false,"sender":{"key":"git@nedharvey.com","avatar":null},"body":"I have a git server hosted on https (github enterprise virtual appliance),\nusing a valid signed cert from startcom, which passes all the SSL checks for\nany browser I use on any OS (IE, Firefox, Safari, Chrome, on Ubuntu, Mac\nOSX, MS Win7) but when I connect to it using git, git complains about the\ncert, but it's platform dependent, and it doesn't seem to make any sense... \nDoes git have its own set of SSL trusted root CA's compiled in at build time\nor something?  It seems weird that it's apparently not using the trusted\nroot CA's from the OS...\n\nI have not tried re-signing my cert using a different CA.  I see github uses\nDigiCert.  My clients do not complain about SSL cert when cloning from\ngithub.\n\nThe test command is, simply:\ngit clone https://user@server.com/user/project.git\n(Obviously, using a real username, a real servername, and a real project\nname instead of the line above.)\n\n** On OSX, it works no problem.  This is OSX 10.7 Lion, upgraded from 10.6\nSL, with 4.1 upgraded from XCode 3.2.6.  Git version 1.7.4.4\n\n** On ubuntu, oneiric x86_64, git version 1.7.5.4, it says:\nerror: server certificate verification failed. CAfile:\n/etc/ssl/certs/ca-certificates.crt CRLfile: none while accessing\nhttps://user@server.com/user/project.git/info/refs\nfatal: HTTP request failed\n\nThis is annoying, because ... It names the location where it's searching for\nthe root certificates, so I thought maybe the startcom root CA wasn't in\nthere, so I went and looked, and confirmed it's there.  Compared the actual\npem encoded root ca cert string to the one that signed my server's cert, and\nit's definitely there.\n\nOn linux, users are able to workaround using GIT_SSL_NO_VERIFY=1, but that\nkind of defeats the purpose.  I don't want them doing this.\n\n** On Win 7 64bit, tortoisegit 1.6.5.0 based on git 1.7.3.1, it says:\nerror: SSL certificate problem, verify that the CA cert is OK. Details:\nerror:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify\nfailed while accessing https://user@server.com/user/project.git/info/refs\nfatal: HTTP request failed\nCloning into C:\\workdir\n\nI don't see any way to workaround, but haven't looked very hard for a\nwindows equivalent of GIT_SSL_NO_VERIFY\n\n** On Win 7 64bit, cygwin git version 1.7.9, it says:\nerror: SSL certificate problem, verify that the CA cert is OK. Details:\nerror:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate verify\nfailed while accessing https://user@server.com/user/project.git/info/refs \nfatal: HTTP request failed\n\nAlso, it ignores the presence of GIT_SSL_NO_VERIFY.  So there isn't any\nknown workaround for cygwin.\n"},{"id":"185345","messageId":"CAJo=hJuyHv_L_zajW-MWEj6fDGggrVDkRWT32mD5TBzD_GzReQ@mail.gmail.com","threadId":"29726","inReplyTo":"000501ccf328$1efe1070$5cfa3150$@nedharvey.com","subject":"Re: git and SSL certificates","fromName":"Shawn Pearce","fromEmail":"spearce@spearce.org","sentAt":"2012-02-24T19:27:21Z","receivedAt":"2012-02-24T19:27:21Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"On Fri, Feb 24, 2012 at 11:11, Edward Ned Harvey <git@nedharvey.com> wrote:\n> I have a git server hosted on https (github enterprise virtual appliance),\n> using a valid signed cert from startcom, which passes all the SSL checks for\n> any browser I use on any OS (IE, Firefox, Safari, Chrome, on Ubuntu, Mac\n> OSX, MS Win7) but when I connect to it using git, git complains about the\n> cert, but it's platform dependent, and it doesn't seem to make any sense...\n> Does git have its own set of SSL trusted root CA's compiled in at build time\n> or something?  It seems weird that it's apparently not using the trusted\n> root CA's from the OS...\n\nNope. Git uses the system's libcurl, which is probably using the\nsystem's libssl or libgnutls, which is using the system's\ncertificates.\n"},{"id":"185353","messageId":"000801ccf32f$2448e030$6cdaa090$@nedharvey.com","threadId":"29726","inReplyTo":"CAJo=hJuyHv_L_zajW-MWEj6fDGggrVDkRWT32mD5TBzD_GzReQ@mail.gmail.com","subject":"RE: git and SSL certificates","fromName":"Edward Ned Harvey","fromEmail":"git@nedharvey.com","sentAt":"2012-02-24T20:01:42Z","receivedAt":"2012-02-24T20:01:42Z","isPatch":false,"sender":{"key":"git@nedharvey.com","avatar":null},"body":"> From: Shawn Pearce [mailto:spearce@spearce.org]\n> Sent: Friday, February 24, 2012 2:27 PM\n>\n> Nope. Git uses the system's libcurl, which is probably using the\n> system's libssl or libgnutls, which is using the system's\n> certificates.\n\nThanks, this gives me more fuel to go on, because now I know I can reproduce\nthe problem using any other tool I want - curl for example.  Where I'm able\nto specify -v for verbose, and get its cert search path.\n\nIt's still really bizarre, because the Startcom root CA is indeed present in\nthe search path, and it is indeed the same root CA that was used to sign my\nserver cert.  So now I'll go ask startcom what they think about it...\n\nIf anyone is interested, please say so, and I'll report back here.\nOtherwise, I'll probably just let the thread die.\n"}]}