{"thread":{"id":"39268","subject":"[PATCH] add support for specifying an SSL cipher list","startedAt":"2015-05-07T14:16:50Z","lastAt":"2015-05-14T19:39:20Z","messageCount":20,"participants":["Lars Kellogg-Stedman","Junio C Hamano","Tay Ray Chuan","Eric Sunshine","SZEDER Gábor"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"260727","messageId":"1431008210-673-1-git-send-email-lars@redhat.com","threadId":"39268","inReplyTo":null,"subject":"[PATCH] add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T14:16:50Z","receivedAt":"2015-05-07T14:16:50Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"Teach git about a new option, \"http.sslCipherList\", which permits one to\nspecify a list of ciphers to use when negotiating SSL connections.  The\nsetting can be overwridden by the GIT_SSL_CIPHER_LIST environment\nvariable.\n\nSigned-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n---\n\nI was recently helping someone diagnose the following error when\ntrying to clone a remote repository:\n\n  fatal: unable to access 'https://example.org/': Cannot communicate\n  securely with peer: no common encryption algorithm(s).\n\nThis happens when the remote server and the default libcurl\nconfiguration do not share any ciphers in common.  In this particular\ncase the solution was to add 'ecdhe_ecdsa_aes_128_gcm_sha_256' to the\nlist of ciphers via CURLOPT_SSL_CIPHER_LIST.  This patch permits one\nto make such a configuration change in git.\n\n Documentation/config.txt |  7 +++++++\n http.c                   | 11 +++++++++++\n 2 files changed, 18 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex 2e5ceaf..b17985c 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1560,6 +1560,13 @@ http.saveCookies::\n \tIf set, store cookies received during requests to the file specified by\n \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n \n+http.sslCipherList::\n+  A list of SSL ciphers to use when negotiating an SSL connection.\n+  The available ciphers depend on whether libcurl was built against\n+  NSS or OpenSSL and the particular configuration of the crypto\n+  library in use.  Can be overwridden by the 'GIT_SSL_CIPHER_LIST'\n+  environment variable.\n+\n http.sslVerify::\n \tWhether to verify the SSL certificate when fetching or pushing\n \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\ndiff --git a/http.c b/http.c\nindex 4b179f6..8077f8d 100644\n--- a/http.c\n+++ b/http.c\n@@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n static int curl_ssl_verify = -1;\n static int curl_ssl_try;\n static const char *ssl_cert;\n+static const char *ssl_cipherlist;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n #endif\n@@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\tcurl_ssl_verify = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.sslcipherlist\", var)) {\n+\t\treturn git_config_string(&ssl_cipherlist, var, value);\n+\t}\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n #if LIBCURL_VERSION_NUM >= 0x070903\n@@ -361,6 +365,13 @@ static CURL *get_curl_handle(void)\n \tif (http_proactive_auth)\n \t\tinit_curl_http_auth(result);\n \n+\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n+\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n+\n+\tif (ssl_cipherlist != NULL)\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n+\t\t\t\tssl_cipherlist);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n2.4.0\n"},{"id":"260730","messageId":"xmqq8ud0s7sv.fsf@gitster.dls.corp.google.com","threadId":"39268","inReplyTo":"1431008210-673-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-05-07T15:53:36Z","receivedAt":"2015-05-07T15:53:36Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Lars Kellogg-Stedman <lars@redhat.com> writes:\n\n> Teach git about a new option, \"http.sslCipherList\", which permits one to\n> specify a list of ciphers to use when negotiating SSL connections.  The\n> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n> variable.\n>\n> Signed-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n> ---\n>\n> I was recently helping someone diagnose the following error when\n> trying to clone a remote repository:\n>\n>   fatal: unable to access 'https://example.org/': Cannot communicate\n>   securely with peer: no common encryption algorithm(s).\n>\n> This happens when the remote server and the default libcurl\n> configuration do not share any ciphers in common.  In this particular\n> case the solution was to add 'ecdhe_ecdsa_aes_128_gcm_sha_256' to the\n> list of ciphers via CURLOPT_SSL_CIPHER_LIST.  This patch permits one\n> to make such a configuration change in git.\n>\n>  Documentation/config.txt |  7 +++++++\n>  http.c                   | 11 +++++++++++\n>  2 files changed, 18 insertions(+)\n>\n> diff --git a/Documentation/config.txt b/Documentation/config.txt\n> index 2e5ceaf..b17985c 100644\n> --- a/Documentation/config.txt\n> +++ b/Documentation/config.txt\n> @@ -1560,6 +1560,13 @@ http.saveCookies::\n>  \tIf set, store cookies received during requests to the file specified by\n>  \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n>  \n> +http.sslCipherList::\n> +  A list of SSL ciphers to use when negotiating an SSL connection.\n> +  The available ciphers depend on whether libcurl was built against\n> +  NSS or OpenSSL and the particular configuration of the crypto\n> +  library in use.  Can be overwridden by the 'GIT_SSL_CIPHER_LIST'\n> +  environment variable.\n\nIt is not clear to me what definition of \"override\" this sentence\nuses.  If you set something to this configuration variable, and if\nyou want to revert the list back to whatever cURL uses by default,\nwhat exact value should I set GIT_SSL_CIPHER_LIST to?  Do I have to\nfind out the list of cipher suites cURL uses by default from the doc\nand list them all in the correct order, or can I merely set it to an\nempty string, i.e.\n\n\t$ GIT_SSL_CIPHER_LIST= git fetch ...\n\nor what?\n\nI also wonder if this feature is something we would want a test or\ntwo to protect against future changes accidentally breaking it, but\nI do not offhand know how hard it would be to come up with a\nreasonable test.\n\nThanks.\n\n> diff --git a/http.c b/http.c\n> index 4b179f6..8077f8d 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n>  static int curl_ssl_verify = -1;\n>  static int curl_ssl_try;\n>  static const char *ssl_cert;\n> +static const char *ssl_cipherlist;\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n>  static const char *ssl_key;\n>  #endif\n> @@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n>  \t\tcurl_ssl_verify = git_config_bool(var, value);\n>  \t\treturn 0;\n>  \t}\n> +\tif (!strcmp(\"http.sslcipherlist\", var)) {\n> +\t\treturn git_config_string(&ssl_cipherlist, var, value);\n> +\t}\n>  \tif (!strcmp(\"http.sslcert\", var))\n>  \t\treturn git_config_string(&ssl_cert, var, value);\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n> @@ -361,6 +365,13 @@ static CURL *get_curl_handle(void)\n>  \tif (http_proactive_auth)\n>  \t\tinit_curl_http_auth(result);\n>  \n> +\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n> +\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n> +\n> +\tif (ssl_cipherlist != NULL)\n> +\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n> +\t\t\t\tssl_cipherlist);\n> +\n>  \tif (ssl_cert != NULL)\n>  \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n>  \tif (has_cert_password())\n"},{"id":"260732","messageId":"20150507160413.GB16334@redhat.com","threadId":"39268","inReplyTo":"xmqq8ud0s7sv.fsf@gitster.dls.corp.google.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T16:04:13Z","receivedAt":"2015-05-07T16:04:13Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"[Apologies for the dupe; this should have been cc'd to the list]\n\n> It is not clear to me what definition of \"override\" this sentence\n> uses.\n\nI was using it in what I thought was the common sense of \"git will use\nthe value in the environment variable if it exists rather than any\nvalue in the git configuration\".  I apologize if this wasn't clear;\ncan you suggest how I might rephrase that?\n\n> If you set something to this configuration variable, and if\n> you want to revert the list back to whatever cURL uses by default,\n> what exact value should I set GIT_SSL_CIPHER_LIST to?\n\nSo, with the current version of the patch there isn't an easy way to\nsay, \"use the defaults instead of what is in my git configuration\".\nSetting GIT_SSL_CIPHER_LIST to an empty string would simply disable\nSSL.\n\nI'll submit a new version of the patch that treats an emtpy cipher\nlist as meaning, \"do not explicitly set CURLOPT_SSL_CIPHER_LIST\".\n\n> I also wonder if this feature is something we would want a test or\n> two to protect against future changes accidentally breaking it, but\n> I do not offhand know how hard it would be to come up with a\n> reasonable test.\n\nYeah, I looked briefly through the tests but I didn't see any existing\nSSL tests and wasn't sure where to start.  I'm open to suggestions on\nthis front.\n\n-- \nLars Kellogg-Stedman <lars@redhat.com> | larsks @ {freenode,twitter,github}\nCloud Engineering / OpenStack          | http://blog.oddbit.com/\n\n"},{"id":"260734","messageId":"1431014932-19236-1-git-send-email-lars@redhat.com","threadId":"39268","inReplyTo":"xmqq8ud0s7sv.fsf@gitster.dls.corp.google.com","subject":"[PATCH v2] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T16:08:52Z","receivedAt":"2015-05-07T16:08:52Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"Teach git about a new option, \"http.sslCipherList\", which permits one to\nspecify a list of ciphers to use when negotiating SSL connections.  The\nsetting can be overwridden by the GIT_SSL_CIPHER_LIST environment\nvariable.\n\nSigned-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n---\n Documentation/config.txt |  8 ++++++++\n http.c                   | 11 +++++++++++\n 2 files changed, 19 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex 2e5ceaf..b0af723 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1560,6 +1560,14 @@ http.saveCookies::\n \tIf set, store cookies received during requests to the file specified by\n \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n \n+http.sslCipherList::\n+  A list of SSL ciphers to use when negotiating an SSL connection.\n+  The available ciphers depend on whether libcurl was built against\n+  NSS or OpenSSL and the particular configuration of the crypto\n+  library in use.  Can be overwridden by the 'GIT_SSL_CIPHER_LIST'\n+  environment variable.  To force git to use libcurl's default cipher\n+  list, set GIT_SSL_CIPHER_LIST to the empty string.\n+\n http.sslVerify::\n \tWhether to verify the SSL certificate when fetching or pushing\n \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\ndiff --git a/http.c b/http.c\nindex 4b179f6..55adff1 100644\n--- a/http.c\n+++ b/http.c\n@@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n static int curl_ssl_verify = -1;\n static int curl_ssl_try;\n static const char *ssl_cert;\n+static const char *ssl_cipherlist;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n #endif\n@@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\tcurl_ssl_verify = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.sslcipherlist\", var)) {\n+\t\treturn git_config_string(&ssl_cipherlist, var, value);\n+\t}\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n #if LIBCURL_VERSION_NUM >= 0x070903\n@@ -361,6 +365,13 @@ static CURL *get_curl_handle(void)\n \tif (http_proactive_auth)\n \t\tinit_curl_http_auth(result);\n \n+\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n+\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n+\n+\tif (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n+\t\t\t\tssl_cipherlist);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n2.4.0\n"},{"id":"260741","messageId":"xmqqvbg4qreq.fsf@gitster.dls.corp.google.com","threadId":"39268","inReplyTo":"20150507160413.GB16334@redhat.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-05-07T16:33:01Z","receivedAt":"2015-05-07T16:33:01Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Lars Kellogg-Stedman <lars@redhat.com> writes:\n\n> [Apologies for the dupe; this should have been cc'd to the list]\n>\n>> It is not clear to me what definition of \"override\" this sentence\n>> uses.\n>\n> I was using it in what I thought was the common sense of \"git will use\n> the value in the environment variable if it exists rather than any\n> value in the git configuration\".  I apologize if this wasn't clear;\n> can you suggest how I might rephrase that?\n\nI was hinting that the usual \"override\" that needs to specify\nthe list to be used exactly would not be very useful, in that\npeople often want to say one of the three things:\n\n - allow this to be used in addition to what you usually use; or\n\n - what you usually use is fine, but never use this one as it was\n   recently discovered to be insecure; or\n\n - I have something nonstandard configured but ignore that\n   configuration for this invocation only and reset to the default\n   behaviour.\n\nIf you are changing the behaviour in your reroll, I suspect you\nwouldn't be doing the common \"override\".  If you are going to do the\n'reset on empty', then 'You can set the environment variable to an\nempty string to reset to the default cipher list used by libcURL.'\nmay be a natural way to describe it.\n\nI briefly wondered if lack of the other two (\"allow this too\",\n\"forbid this\") might become an issue not just for the environment,\nbut also for the configuration variable.  It is probably not a huge\nissue because you can say \"http.<url>.sslCipherList\" to limit the\nscope of the affected site [*1*].\n\nCURLOPT_SSL_CIPHER_LIST appeared in cURL 7.9 which is relatively\nancient, so it should be safe to use (please write that down in your\ncommit log message).\n\nThanks.\n\n\n[Footnote]\n\n*1* And it is a bad idea to address \"allow this too\" and \"forbid\n    this\" at our level---the semantics of CURLOPT_SSL_CIPHER_LIST\n    given by libcURL itself depends on the crypto backend (when\n    using OpenSSL and GnuTLS, you can say !, +, - to tweak; when\n    using NSS, you can only say \"use these and nothing else\").\n"},{"id":"260743","messageId":"CALUzUxoC66QZ5gJdV_nE=zFOLUNfpz64Ena2rDmesaEqkEGDAQ@mail.gmail.com","threadId":"39268","inReplyTo":"1431008210-673-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Tay Ray Chuan","fromEmail":"rctay89@gmail.com","sentAt":"2015-05-07T16:42:02Z","receivedAt":"2015-05-07T16:42:02Z","isPatch":true,"sender":{"key":"rctay89@gmail.com","avatar":"https://avatars.githubusercontent.com/u/61553?v=4"},"body":"On Thu, May 7, 2015 at 10:16 PM, Lars Kellogg-Stedman <lars@redhat.com> wrote:\n> diff --git a/Documentation/config.txt b/Documentation/config.txt\n> index 2e5ceaf..b17985c 100644\n> --- a/Documentation/config.txt\n> +++ b/Documentation/config.txt\n> @@ -1560,6 +1560,13 @@ http.saveCookies::\n>         If set, store cookies received during requests to the file specified by\n>         http.cookieFile. Has no effect if http.cookieFile is unset.\n>\n> +http.sslCipherList::\n> +  A list of SSL ciphers to use when negotiating an SSL connection.\n> +  The available ciphers depend on whether libcurl was built against\n> +  NSS or OpenSSL and the particular configuration of the crypto\n> +  library in use.  Can be overwridden by the 'GIT_SSL_CIPHER_LIST'\n> +  environment variable.\n> +\n>  http.sslVerify::\n>         Whether to verify the SSL certificate when fetching or pushing\n>         over HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\n\nYou might want to mention the libcurl option that this conf\ncorresponds to, so that a reader could go look it up in the libcurl\ndocumentation to get an idea of the ciphers available, and list syntax\nto be used that would be accepted by us (but really by libcurl). But\nwe also don't have to go as far as reproducing it here (eg. ciphers\nseparated by colons) since this it tied to the libcurl version the\nuser is linking against.\n\n-- \nCheers,\nRay Chuan\n"},{"id":"260746","messageId":"20150507165721.GC16334@redhat.com","threadId":"39268","inReplyTo":"CALUzUxoC66QZ5gJdV_nE=zFOLUNfpz64Ena2rDmesaEqkEGDAQ@mail.gmail.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T16:57:21Z","receivedAt":"2015-05-07T16:57:21Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"On Fri, May 08, 2015 at 12:42:02AM +0800, Tay Ray Chuan wrote:\n> You might want to mention the libcurl option that this conf\n> corresponds to, so that a reader could go look it up in the libcurl\n> documentation to get an idea of the ciphers available...\n\nI actually removed references to the specific option before submitting\nthe patch, because none of the other settings that affect curl options\nexplicitly document the corresponding curl option name.  But I am\nhappy to add it back.\n\n> to be used that would be accepted by us (but really by libcurl). But\n> we also don't have to go as far as reproducing it here (eg. ciphers\n> separated by colons) since this it tied to the libcurl version the\n> user is linking against.\n\nRight, I think that documenting the curl option is sufficient, and\nthen people can consult the libcurl documentation if they need\ndetails.\n\n-- \nLars Kellogg-Stedman <lars@redhat.com> | larsks @ {freenode,twitter,github}\nCloud Engineering / OpenStack          | http://blog.oddbit.com/\n\n"},{"id":"260747","messageId":"20150507165841.GD16334@redhat.com","threadId":"39268","inReplyTo":"xmqqvbg4qreq.fsf@gitster.dls.corp.google.com","subject":"Re: [PATCH] add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T16:58:41Z","receivedAt":"2015-05-07T16:58:41Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"On Thu, May 07, 2015 at 09:33:01AM -0700, Junio C Hamano wrote:\n> If you are changing the behaviour in your reroll, I suspect you\n> wouldn't be doing the common \"override\".  If you are going to do the\n> 'reset on empty', then 'You can set the environment variable to an\n> empty string to reset to the default cipher list used by libcURL.'\n> may be a natural way to describe it.\n\nThanks for your comments.  I will work on rephrasing things a bit.\n\n-- \nLars Kellogg-Stedman <lars@redhat.com> | larsks @ {freenode,twitter,github}\nCloud Engineering / OpenStack          | http://blog.oddbit.com/\n\n"},{"id":"260763","messageId":"1431022630-7005-1-git-send-email-lars@redhat.com","threadId":"39268","inReplyTo":"1431008210-673-1-git-send-email-lars@redhat.com","subject":"[PATCH v3] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T18:17:10Z","receivedAt":"2015-05-07T18:17:10Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"Teach git about a new option, \"http.sslCipherList\", which permits one to\nspecify a list of ciphers to use when negotiating SSL connections.  The\nsetting can be overwridden by the GIT_SSL_CIPHER_LIST environment\nvariable.\n\nSigned-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n---\n\nThis addresses (I hope!) comments from Junio and Ray, and also resolves some\nwhitespace issues present in the earlier version of the patch.\n\n Documentation/config.txt | 13 +++++++++++++\n http.c                   | 14 ++++++++++++++\n 2 files changed, 27 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex 2e5ceaf..b982d66 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1560,6 +1560,19 @@ http.saveCookies::\n \tIf set, store cookies received during requests to the file specified by\n \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n \n+http.sslCipherList::\n+\tA list of SSL ciphers to use when negotiating an SSL connection.\n+\tThe available ciphers depend on whether libcurl was built against\n+\tNSS or OpenSSL and the particular configuration of the crypto\n+\tlibrary in use.  Internally this sets the CURLOPT_SSL_CIPHER_LIST\n+\toption; see the libcurl documentation for that option for more\n+\tdetails on the format of this list.\n+\n+\tCan be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n+\tTo force git to use libcurl's default cipher list and ignore any\n+\texplicit http.sslCipherList option, set GIT_SSL_CIPHER_LIST to the\n+\tempty string.\n+\n http.sslVerify::\n \tWhether to verify the SSL certificate when fetching or pushing\n \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\ndiff --git a/http.c b/http.c\nindex 4b179f6..b617546 100644\n--- a/http.c\n+++ b/http.c\n@@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n static int curl_ssl_verify = -1;\n static int curl_ssl_try;\n static const char *ssl_cert;\n+static const char *ssl_cipherlist;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n #endif\n@@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\tcurl_ssl_verify = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.sslcipherlist\", var)) {\n+\t\treturn git_config_string(&ssl_cipherlist, var, value);\n+\t}\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n #if LIBCURL_VERSION_NUM >= 0x070903\n@@ -361,6 +365,16 @@ static CURL *get_curl_handle(void)\n \tif (http_proactive_auth)\n \t\tinit_curl_http_auth(result);\n \n+\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n+\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n+\n+\t/* See http://curl.haxx.se/libcurl/c/CURLOPT_SSL_CIPHER_LIST.html\n+\t * for details on the format of and available values for\n+\t * CURLOPT_SSL_CIPHER_LIST. */\n+\tif (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n+\t\t\t\tssl_cipherlist);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n2.4.0\n"},{"id":"260770","messageId":"CAPig+cSPGguo1mEqfCTpLbHuCMaKkH8YQhoDCOPM82Fjt0C+eg@mail.gmail.com","threadId":"39268","inReplyTo":"1431022630-7005-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH v3] http: add support for specifying an SSL cipher list","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-05-07T18:41:07Z","receivedAt":"2015-05-07T18:41:07Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Thu, May 7, 2015 at 2:17 PM, Lars Kellogg-Stedman <lars@redhat.com> wrote:\n> Teach git about a new option, \"http.sslCipherList\", which permits one to\n> specify a list of ciphers to use when negotiating SSL connections.  The\n> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n> variable.\n>\n> Signed-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n> ---\n> diff --git a/Documentation/config.txt b/Documentation/config.txt\n> index 2e5ceaf..b982d66 100644\n> --- a/Documentation/config.txt\n> +++ b/Documentation/config.txt\n> @@ -1560,6 +1560,19 @@ http.saveCookies::\n>         If set, store cookies received during requests to the file specified by\n>         http.cookieFile. Has no effect if http.cookieFile is unset.\n>\n> +http.sslCipherList::\n> +       A list of SSL ciphers to use when negotiating an SSL connection.\n> +       The available ciphers depend on whether libcurl was built against\n> +       NSS or OpenSSL and the particular configuration of the crypto\n> +       library in use.  Internally this sets the CURLOPT_SSL_CIPHER_LIST\n> +       option; see the libcurl documentation for that option for more\n> +       details on the format of this list.\n> +\n> +       Can be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n> +       To force git to use libcurl's default cipher list and ignore any\n> +       explicit http.sslCipherList option, set GIT_SSL_CIPHER_LIST to the\n> +       empty string.\n\nMuch nicer description than previous rounds.\n\nA couple style nits below.\n\n>  http.sslVerify::\n>         Whether to verify the SSL certificate when fetching or pushing\n>         over HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\n> diff --git a/http.c b/http.c\n> index 4b179f6..b617546 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n>  static int curl_ssl_verify = -1;\n>  static int curl_ssl_try;\n>  static const char *ssl_cert;\n> +static const char *ssl_cipherlist;\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n>  static const char *ssl_key;\n>  #endif\n> @@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n>                 curl_ssl_verify = git_config_bool(var, value);\n>                 return 0;\n>         }\n> +       if (!strcmp(\"http.sslcipherlist\", var)) {\n> +               return git_config_string(&ssl_cipherlist, var, value);\n> +       }\n>         if (!strcmp(\"http.sslcert\", var))\n>                 return git_config_string(&ssl_cert, var, value);\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n> @@ -361,6 +365,16 @@ static CURL *get_curl_handle(void)\n>         if (http_proactive_auth)\n>                 init_curl_http_auth(result);\n>\n> +       if (getenv(\"GIT_SSL_CIPHER_LIST\"))\n> +               ssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n> +\n> +       /* See http://curl.haxx.se/libcurl/c/CURLOPT_SSL_CIPHER_LIST.html\n> +        * for details on the format of and available values for\n> +        * CURLOPT_SSL_CIPHER_LIST. */\n\nFormat multi-line comments like this:\n\n    /*\n     * This is a multi-line\n     * comment.\n     */\n\n> +       if (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n\nIn git code, this is usually spelled:\n\n    if (ssl_cipherlist && *ssl_cipherlist)\n\n> +               curl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n> +                               ssl_cipherlist);\n>+\n>         if (ssl_cert != NULL)\n>                 curl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n>         if (has_cert_password())\n> --\n> 2.4.0\n"},{"id":"260772","messageId":"20150507184804.GF16334@redhat.com","threadId":"39268","inReplyTo":"CAPig+cSPGguo1mEqfCTpLbHuCMaKkH8YQhoDCOPM82Fjt0C+eg@mail.gmail.com","subject":"Re: [PATCH v3] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-07T18:48:04Z","receivedAt":"2015-05-07T18:48:04Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"On Thu, May 07, 2015 at 02:41:07PM -0400, Eric Sunshine wrote:\n> Format multi-line comments like this:\n> \n>     /*\n>      * This is a multi-line\n>      * comment.\n>      */\n\nNoted, thanks.\n\n> > +       if (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n> \n> In git code, this is usually spelled:\n> \n>     if (ssl_cipherlist && *ssl_cipherlist)\n\nHuh.  At least in http.c, explicit checks against NULL seem more\ncommon:\n\n    if (ssl_cert != NULL)\n    if (ssl_key != NULL)\n    if (ssl_capath != NULL)\n\nEtc.  I was just trying to make the new code look like the existing\ncode.  If nobody else has an opinion on this, I'm inclined to leave\nthe first clause as-is so that it matches and change the check for an\nempty string.\n\n-- \nLars Kellogg-Stedman <lars@redhat.com> | larsks @ {freenode,twitter,github}\nCloud Engineering / OpenStack          | http://blog.oddbit.com/\n\n"},{"id":"260774","messageId":"CAPig+cQG-yjmw6uMN0bL-3jYhgffi5Mc6rOsRePTLBvXpfdiKQ@mail.gmail.com","threadId":"39268","inReplyTo":"20150507184804.GF16334@redhat.com","subject":"Re: [PATCH v3] http: add support for specifying an SSL cipher list","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-05-07T18:54:07Z","receivedAt":"2015-05-07T18:54:07Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Thu, May 7, 2015 at 2:48 PM, Lars Kellogg-Stedman <lars@redhat.com> wrote:\n> On Thu, May 07, 2015 at 02:41:07PM -0400, Eric Sunshine wrote:\n>> > +       if (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n>>\n>> In git code, this is usually spelled:\n>>\n>>     if (ssl_cipherlist && *ssl_cipherlist)\n>\n> Huh.  At least in http.c, explicit checks against NULL seem more\n> common:\n>\n>     if (ssl_cert != NULL)\n>     if (ssl_key != NULL)\n>     if (ssl_capath != NULL)\n>\n> Etc.  I was just trying to make the new code look like the existing\n> code.  If nobody else has an opinion on this, I'm inclined to leave\n> the first clause as-is so that it matches and change the check for an\n> empty string.\n\nSounds good. Matching existing style makes sense.\n"},{"id":"260782","messageId":"xmqqegmsnmaz.fsf@gitster.dls.corp.google.com","threadId":"39268","inReplyTo":"1431022630-7005-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH v3] http: add support for specifying an SSL cipher list","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-05-07T20:51:32Z","receivedAt":"2015-05-07T20:51:32Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Lars Kellogg-Stedman <lars@redhat.com> writes:\n\n> Teach git about a new option, \"http.sslCipherList\", which permits one to\n> specify a list of ciphers to use when negotiating SSL connections.  The\n> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n> variable.\n>\n> Signed-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n> ---\n>\n> This addresses (I hope!) comments from Junio and Ray, and also resolves some\n> whitespace issues present in the earlier version of the patch.\n\nSounds good.\n\n>  Documentation/config.txt | 13 +++++++++++++\n>  http.c                   | 14 ++++++++++++++\n>  2 files changed, 27 insertions(+)\n>\n> diff --git a/Documentation/config.txt b/Documentation/config.txt\n> index 2e5ceaf..b982d66 100644\n> --- a/Documentation/config.txt\n> +++ b/Documentation/config.txt\n> @@ -1560,6 +1560,19 @@ http.saveCookies::\n>  \tIf set, store cookies received during requests to the file specified by\n>  \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n>  \n> +http.sslCipherList::\n> +\tA list of SSL ciphers to use when negotiating an SSL connection.\n> +\tThe available ciphers depend on whether libcurl was built against\n> +\tNSS or OpenSSL and the particular configuration of the crypto\n> +\tlibrary in use.  Internally this sets the CURLOPT_SSL_CIPHER_LIST\n> +\toption; see the libcurl documentation for that option for more\n> +\tdetails on the format of this list.\n> +\n> +\tCan be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n> +\tTo force git to use libcurl's default cipher list and ignore any\n> +\texplicit http.sslCipherList option, set GIT_SSL_CIPHER_LIST to the\n> +\tempty string.\n> +\n\nThis will not format well, I am afraid.  The second and subsequent\nparagraphs in a description of an enumerated item need to lose the\ninitial indentation and the empty line that breaks paragraph need\nto be replaced with a single '+' (plus).  See \"color::\" in the same\ndocument for an example.\n\nWe chose to use AsciiDoc primarily because its marked-up source is\neasily read as a plain text files, but it is unfortunately somewhat\nfinicky around here.\n\n>  http.sslVerify::\n>  \tWhether to verify the SSL certificate when fetching or pushing\n>  \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\n> diff --git a/http.c b/http.c\n> index 4b179f6..b617546 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n>  static int curl_ssl_verify = -1;\n>  static int curl_ssl_try;\n>  static const char *ssl_cert;\n> +static const char *ssl_cipherlist;\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n>  static const char *ssl_key;\n>  #endif\n> @@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n>  \t\tcurl_ssl_verify = git_config_bool(var, value);\n>  \t\treturn 0;\n>  \t}\n> +\tif (!strcmp(\"http.sslcipherlist\", var)) {\n> +\t\treturn git_config_string(&ssl_cipherlist, var, value);\n> +\t}\n>  \tif (!strcmp(\"http.sslcert\", var))\n>  \t\treturn git_config_string(&ssl_cert, var, value);\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n> @@ -361,6 +365,16 @@ static CURL *get_curl_handle(void)\n>  \tif (http_proactive_auth)\n>  \t\tinit_curl_http_auth(result);\n>  \n> +\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n> +\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n> +\n> +\t/* See http://curl.haxx.se/libcurl/c/CURLOPT_SSL_CIPHER_LIST.html\n> +\t * for details on the format of and available values for\n> +\t * CURLOPT_SSL_CIPHER_LIST. */\n\nI see Eric already commented on multi-line comment and what he said\nis correct, but as an in-code comment, I do not see much value in\nthis---anybody who is _reading_ code would know to look up\nCURLOPT_SSL_CIPHER_LIST in cURL documentation, I would expect (and\nof course this will not be shown to the end user).\n\n> +\tif (ssl_cipherlist != NULL && ssl_cipherlist[0] != '\\0')\n> +\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n> +\t\t\t\tssl_cipherlist);\n> +\n>  \tif (ssl_cert != NULL)\n>  \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n>  \tif (has_cert_password())\n"},{"id":"260795","messageId":"1431056685-12337-1-git-send-email-lars@redhat.com","threadId":"39268","inReplyTo":"1431008210-673-1-git-send-email-lars@redhat.com","subject":"[PATCH v4] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-08T03:44:45Z","receivedAt":"2015-05-08T03:44:45Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"Teach git about a new option, \"http.sslCipherList\", which permits one to\nspecify a list of ciphers to use when negotiating SSL connections.  The\nsetting can be overwridden by the GIT_SSL_CIPHER_LIST environment\nvariable.\n\nSigned-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n---\n Documentation/config.txt | 13 +++++++++++++\n http.c                   | 11 +++++++++++\n 2 files changed, 24 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex 2e5ceaf..e3f95a2 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1560,6 +1560,19 @@ http.saveCookies::\n \tIf set, store cookies received during requests to the file specified by\n \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n \n+http.sslCipherList::\n+  A list of SSL ciphers to use when negotiating an SSL connection.\n+  The available ciphers depend on whether libcurl was built against\n+  NSS or OpenSSL and the particular configuration of the crypto\n+  library in use.  Internally this sets the 'CURLOPT_SSL_CIPHER_LIST'\n+  option; see the libcurl documentation for more details on the format\n+  of this list.\n++\n+Can be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n+To force git to use libcurl's default cipher list and ignore any\n+explicit http.sslCipherList option, set 'GIT_SSL_CIPHER_LIST' to the\n+empty string.\n+\n http.sslVerify::\n \tWhether to verify the SSL certificate when fetching or pushing\n \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\ndiff --git a/http.c b/http.c\nindex 4b179f6..3a39d07 100644\n--- a/http.c\n+++ b/http.c\n@@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n static int curl_ssl_verify = -1;\n static int curl_ssl_try;\n static const char *ssl_cert;\n+static const char *ssl_cipherlist;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n #endif\n@@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\tcurl_ssl_verify = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.sslcipherlist\", var)) {\n+\t\treturn git_config_string(&ssl_cipherlist, var, value);\n+\t}\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n #if LIBCURL_VERSION_NUM >= 0x070903\n@@ -361,6 +365,13 @@ static CURL *get_curl_handle(void)\n \tif (http_proactive_auth)\n \t\tinit_curl_http_auth(result);\n \n+\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n+\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n+\n+\tif (ssl_cipherlist != NULL && *ssl_cipherlist)\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n+\t\t\t\tssl_cipherlist);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n2.4.0\n"},{"id":"260796","messageId":"CAPig+cSvau6=TGrse0J86MY2Sb0qRfoOQybhLkfqCCS2s7NQXQ@mail.gmail.com","threadId":"39268","inReplyTo":"1431056685-12337-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH v4] http: add support for specifying an SSL cipher list","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-05-08T03:53:19Z","receivedAt":"2015-05-08T03:53:19Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Thu, May 7, 2015 at 11:44 PM, Lars Kellogg-Stedman <lars@redhat.com> wrote:\n> Teach git about a new option, \"http.sslCipherList\", which permits one to\n> specify a list of ciphers to use when negotiating SSL connections.  The\n> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n> variable.\n>\n> Signed-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n> ---\n> diff --git a/http.c b/http.c\n> index 4b179f6..3a39d07 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -187,6 +188,9 @@ static int http_options(const char *var, const char *value, void *cb)\n>                 curl_ssl_verify = git_config_bool(var, value);\n>                 return 0;\n>         }\n> +       if (!strcmp(\"http.sslcipherlist\", var)) {\n> +               return git_config_string(&ssl_cipherlist, var, value);\n> +       }\n\nStyle nit: None of the other conditionals in http_options() use curly\nbraces when the 'if' body is a one-liner.\n\n>         if (!strcmp(\"http.sslcert\", var))\n>                 return git_config_string(&ssl_cert, var, value);\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n"},{"id":"260809","messageId":"1431087305-8988-1-git-send-email-szeder@ira.uka.de","threadId":"39268","inReplyTo":"1431056685-12337-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH v4] http: add support for specifying an SSL cipher list","fromName":"SZEDER Gábor","fromEmail":"szeder@ira.uka.de","sentAt":"2015-05-08T12:15:05Z","receivedAt":"2015-05-08T12:15:05Z","isPatch":true,"sender":{"key":"szeder.dev@gmail.com","avatar":"https://avatars.githubusercontent.com/u/116324?v=4"},"body":"> +http.sslCipherList::\n> +  A list of SSL ciphers to use when negotiating an SSL connection.\n> +  The available ciphers depend on whether libcurl was built against\n> +  NSS or OpenSSL and the particular configuration of the crypto\n> +  library in use.  Internally this sets the 'CURLOPT_SSL_CIPHER_LIST'\n> +  option; see the libcurl documentation for more details on the format\n> +  of this list.\n> ++\n> +Can be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n> +To force git to use libcurl's default cipher list and ignore any\n> +explicit http.sslCipherList option, set 'GIT_SSL_CIPHER_LIST' to the\n> +empty string.\n> +\n\n... or with 'git -c http.sslCipherList <cmd>' on the command line (but I\ndon't think it should be mentioned here that a config variable from a\nconfig file can be overridden via 'git -c', because that's true for all\nconfig variables anyway).\n\nHowever, speaking of command line, could you please add this new config\nvariable to the completion script (contrib/completion/git-completion.bash,\nsomewhere around line 2120)?  Thanks.\n\nBest,\nG�bor\n"},{"id":"260813","messageId":"1431091335-16455-1-git-send-email-lars@redhat.com","threadId":"39268","inReplyTo":"1431008210-673-1-git-send-email-lars@redhat.com","subject":"[PATCH v5] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-08T13:22:15Z","receivedAt":"2015-05-08T13:22:15Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"Teach git about a new option, \"http.sslCipherList\", which permits one to\nspecify a list of ciphers to use when negotiating SSL connections.  The\nsetting can be overwridden by the GIT_SSL_CIPHER_LIST environment\nvariable.\n\nSigned-off-by: Lars Kellogg-Stedman <lars@redhat.com>\n---\n\nAddressing comments from Gábor and Eric.\n\n Documentation/config.txt               | 13 +++++++++++++\n contrib/completion/git-completion.bash |  1 +\n http.c                                 | 10 ++++++++++\n 3 files changed, 24 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex 2e5ceaf..e3f95a2 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1560,6 +1560,19 @@ http.saveCookies::\n \tIf set, store cookies received during requests to the file specified by\n \thttp.cookieFile. Has no effect if http.cookieFile is unset.\n \n+http.sslCipherList::\n+  A list of SSL ciphers to use when negotiating an SSL connection.\n+  The available ciphers depend on whether libcurl was built against\n+  NSS or OpenSSL and the particular configuration of the crypto\n+  library in use.  Internally this sets the 'CURLOPT_SSL_CIPHER_LIST'\n+  option; see the libcurl documentation for more details on the format\n+  of this list.\n++\n+Can be overridden by the 'GIT_SSL_CIPHER_LIST' environment variable.\n+To force git to use libcurl's default cipher list and ignore any\n+explicit http.sslCipherList option, set 'GIT_SSL_CIPHER_LIST' to the\n+empty string.\n+\n http.sslVerify::\n \tWhether to verify the SSL certificate when fetching or pushing\n \tover HTTPS. Can be overridden by the 'GIT_SSL_NO_VERIFY' environment\ndiff --git a/contrib/completion/git-completion.bash b/contrib/completion/git-completion.bash\nindex 5944c82..43bfc0c 100644\n--- a/contrib/completion/git-completion.bash\n+++ b/contrib/completion/git-completion.bash\n@@ -2123,6 +2123,7 @@ _git_config ()\n \t\thttp.noEPSV\n \t\thttp.postBuffer\n \t\thttp.proxy\n+\t\thttp.sslCipherList\n \t\thttp.sslCAInfo\n \t\thttp.sslCAPath\n \t\thttp.sslCert\ndiff --git a/http.c b/http.c\nindex 4b179f6..f0c5bbc 100644\n--- a/http.c\n+++ b/http.c\n@@ -36,6 +36,7 @@ char curl_errorstr[CURL_ERROR_SIZE];\n static int curl_ssl_verify = -1;\n static int curl_ssl_try;\n static const char *ssl_cert;\n+static const char *ssl_cipherlist;\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n #endif\n@@ -187,6 +188,8 @@ static int http_options(const char *var, const char *value, void *cb)\n \t\tcurl_ssl_verify = git_config_bool(var, value);\n \t\treturn 0;\n \t}\n+\tif (!strcmp(\"http.sslcipherlist\", var))\n+\t\treturn git_config_string(&ssl_cipherlist, var, value);\n \tif (!strcmp(\"http.sslcert\", var))\n \t\treturn git_config_string(&ssl_cert, var, value);\n #if LIBCURL_VERSION_NUM >= 0x070903\n@@ -361,6 +364,13 @@ static CURL *get_curl_handle(void)\n \tif (http_proactive_auth)\n \t\tinit_curl_http_auth(result);\n \n+\tif (getenv(\"GIT_SSL_CIPHER_LIST\"))\n+\t\tssl_cipherlist = getenv(\"GIT_SSL_CIPHER_LIST\");\n+\n+\tif (ssl_cipherlist != NULL && *ssl_cipherlist)\n+\t\tcurl_easy_setopt(result, CURLOPT_SSL_CIPHER_LIST,\n+\t\t\t\tssl_cipherlist);\n+\n \tif (ssl_cert != NULL)\n \t\tcurl_easy_setopt(result, CURLOPT_SSLCERT, ssl_cert);\n \tif (has_cert_password())\n-- \n2.4.0\n"},{"id":"260815","messageId":"xmqqpp6bm562.fsf@gitster.dls.corp.google.com","threadId":"39268","inReplyTo":"1431087305-8988-1-git-send-email-szeder@ira.uka.de","subject":"Re: [PATCH v4] http: add support for specifying an SSL cipher list","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2015-05-08T15:59:17Z","receivedAt":"2015-05-08T15:59:17Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"SZEDER Gábor <szeder@ira.uka.de> writes:\n\n> ... or with 'git -c http.sslCipherList <cmd>' on the command line (but I\n> don't think it should be mentioned here that a config variable from a\n> config file can be overridden via 'git -c', because that's true for all\n> config variables anyway).\n\nI do not think it would be very useful in practice anyway, so I\nagree we should not add it there.  You would not use the blanket\nhttp.sslCipherList but target-specific http.<url>.sslCipherList more\noften to work around specific quirks of one site in your\nconfigurtion, and specifying the blanket form with \"-c\" on the\ncommand line would not defeat that.\n\nSpeaking of urlmatch-assisted configuration variables, do they get\nTAB completed on the command line?\n"},{"id":"261269","messageId":"20150514192552.GB6475@redhat.com","threadId":"39268","inReplyTo":"1431091335-16455-1-git-send-email-lars@redhat.com","subject":"Re: [PATCH v5] http: add support for specifying an SSL cipher list","fromName":"Lars Kellogg-Stedman","fromEmail":"lars@redhat.com","sentAt":"2015-05-14T19:25:52Z","receivedAt":"2015-05-14T19:25:52Z","isPatch":true,"sender":{"key":"lars@redhat.com","avatar":"https://avatars.githubusercontent.com/u/82622?v=4"},"body":"On Fri, May 08, 2015 at 09:22:15AM -0400, Lars Kellogg-Stedman wrote:\n> Teach git about a new option, \"http.sslCipherList\", which permits one to\n> specify a list of ciphers to use when negotiating SSL connections.  The\n> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n> variable.\n\nJunio, et al,\n\nI just wanted to follow up and see if folks were happy with the latest\nversion of the patch.\n\nCheers,\n\n-- \nLars Kellogg-Stedman <lars@redhat.com> | larsks @ {freenode,twitter,github}\nCloud Engineering / OpenStack          | http://blog.oddbit.com/\n\n"},{"id":"261271","messageId":"CAPig+cSuMpQjJRPeaeRdeqWkzJ5Jqde0RuU+OwY=npLwHLP_Aw@mail.gmail.com","threadId":"39268","inReplyTo":"20150514192552.GB6475@redhat.com","subject":"Re: [PATCH v5] http: add support for specifying an SSL cipher list","fromName":"Eric Sunshine","fromEmail":"sunshine@sunshineco.com","sentAt":"2015-05-14T19:39:20Z","receivedAt":"2015-05-14T19:39:20Z","isPatch":true,"sender":{"key":"sunshine@sunshineco.com","avatar":"https://avatars.githubusercontent.com/u/163641?v=4"},"body":"On Thu, May 14, 2015 at 3:25 PM, Lars Kellogg-Stedman <lars@redhat.com> wrote:\n> On Fri, May 08, 2015 at 09:22:15AM -0400, Lars Kellogg-Stedman wrote:\n>> Teach git about a new option, \"http.sslCipherList\", which permits one to\n>> specify a list of ciphers to use when negotiating SSL connections.  The\n>> setting can be overwridden by the GIT_SSL_CIPHER_LIST environment\n>> variable.\n>\n> I just wanted to follow up and see if folks were happy with the latest\n> version of the patch.\n\nHere's what Junio's latest \"What's Cooking\"[1] says:\n\n    * ls/http-ssl-cipher-list (2015-05-08) 1 commit\n     - http: add support for specifying an SSL cipher list\n\n     Introduce http.<url>.SSLCipherList configuration variable to tweak\n     the list of cipher suite to be used with libcURL when talking with\n     https:// sites.\n\n     Will merge to 'next'.\n\nThe \"Will merge to 'next'\" is explained in [2].\n\n[1]: http://article.gmane.org/gmane.comp.version-control.git/268680/\n[2]: http://article.gmane.org/gmane.comp.version-control.git/268100/\n"}]}