{"thread":{"id":"48128","subject":"[PATCH] Allow use of TLS 1.3","startedAt":"2018-03-23T18:27:32Z","lastAt":"2018-03-23T23:37:17Z","messageCount":4,"participants":["Loganaden Velvindron","Ævar Arnfjörð Bjarmason","Johannes Schindelin"],"isPatch":true,"patchVersion":1,"patchTotal":null},"messages":[{"id":"342659","messageId":"20180323182506.GA15493@voidlinux","threadId":"48128","inReplyTo":null,"subject":"[PATCH] Allow use of TLS 1.3","fromName":"Loganaden Velvindron","fromEmail":"logan@hackers.mu","sentAt":"2018-03-23T18:25:06Z","receivedAt":"2018-03-23T18:27:32Z","isPatch":true,"sender":{"key":"logan@hackers.mu","avatar":"https://avatars.githubusercontent.com/u/1688420?v=4"},"body":"Done during IETF 101 hackathon\n\nSigned-off-by: Loganaden Velvindron <logan@hackers.mu>\n---\n Documentation/config.txt | 1 +\n http.c                   | 3 +++\n 2 files changed, 4 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex ce9102cea..f31d62772 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1957,6 +1957,7 @@ http.sslVersion::\n \t- tlsv1.0\n \t- tlsv1.1\n \t- tlsv1.2\n+\t- tlsv1.3\n \n +\n Can be overridden by the `GIT_SSL_VERSION` environment variable.\ndiff --git a/http.c b/http.c\nindex 8c11156ae..666fe31f3 100644\n--- a/http.c\n+++ b/http.c\n@@ -61,6 +61,9 @@ static struct {\n \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n+#if LIBCURL_VERSION_NUM >= 0x075200\n+\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n+#endif\n #endif\n };\n #if LIBCURL_VERSION_NUM >= 0x070903\n-- \n2.16.2\n\n"},{"id":"342662","messageId":"87in9my6y3.fsf@evledraar.gmail.com","threadId":"48128","inReplyTo":"20180323182506.GA15493@voidlinux","subject":"Re: [PATCH] Allow use of TLS 1.3","fromName":"Ævar Arnfjörð Bjarmason","fromEmail":"avarab@gmail.com","sentAt":"2018-03-23T18:37:08Z","receivedAt":"2018-03-23T18:37:17Z","isPatch":true,"sender":{"key":"avarab@gmail.com","avatar":"https://avatars.githubusercontent.com/u/45301?v=4"},"body":"\nOn Fri, Mar 23 2018, Loganaden Velvindron wrote:\n\n> Done during IETF 101 hackathon\n\nHi. Thanks. Let's add a meaningful commit message to this though,\nsomething like:\n\n    Add a tlsv1.3 option to http.sslVersion in addition to the existing\n    tlsv1.[012] options. libcurl has supported this since 7.52.0.\n\n> --- a/http.c\n> +++ b/http.c\n> @@ -61,6 +61,9 @@ static struct {\n>  \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n>  \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n>  \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n> +#if LIBCURL_VERSION_NUM >= 0x075200\n> +\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n> +#endif\n\nI wonder if this wouldn't be better as:\n\n    +#ifdef CURL_SSLVERSION_TLSv1_3\n    +\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n    +#endif\n\nWe've been bitten before by doing version checks on libcurl code, only\nto find that some distros are actively backporting features, so checking\nthe specific macros is usually better.\n\n>  #endif\n>  };\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n"},{"id":"342663","messageId":"20180323183950.GA15994@voidlinux","threadId":"48128","inReplyTo":"87in9my6y3.fsf@evledraar.gmail.com","subject":"Re: [PATCH] Allow use of TLS 1.3","fromName":"Loganaden Velvindron","fromEmail":"logan@hackers.mu","sentAt":"2018-03-23T18:39:50Z","receivedAt":"2018-03-23T18:42:15Z","isPatch":true,"sender":{"key":"logan@hackers.mu","avatar":"https://avatars.githubusercontent.com/u/1688420?v=4"},"body":"On Fri, Mar 23, 2018 at 07:37:08PM +0100, Ævar Arnfjörð Bjarmason wrote:\n> \n> On Fri, Mar 23 2018, Loganaden Velvindron wrote:\n> \n> > Done during IETF 101 hackathon\n> \n> Hi. Thanks. Let's add a meaningful commit message to this though,\n> something like:\n> \n>     Add a tlsv1.3 option to http.sslVersion in addition to the existing\n>     tlsv1.[012] options. libcurl has supported this since 7.52.0.\n\nLooks good to me.\n\n> \n> > --- a/http.c\n> > +++ b/http.c\n> > @@ -61,6 +61,9 @@ static struct {\n> >  \t{ \"tlsv1.0\", CURL_SSLVERSION_TLSv1_0 },\n> >  \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n> >  \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n> > +#if LIBCURL_VERSION_NUM >= 0x075200\n> > +\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n> > +#endif\n> \n> I wonder if this wouldn't be better as:\n> \n>     +#ifdef CURL_SSLVERSION_TLSv1_3\n>     +\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n>     +#endif\n> \n> We've been bitten before by doing version checks on libcurl code, only\n> to find that some distros are actively backporting features, so checking\n> the specific macros is usually better.\n\nThis looks good to me as well. I will send Patch v2, with the suggestions.\n\n> \n> >  #endif\n> >  };\n> >  #if LIBCURL_VERSION_NUM >= 0x070903\n"},{"id":"342710","messageId":"nycvar.QRO.7.76.6.1803240035300.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz","threadId":"48128","inReplyTo":"20180323183950.GA15994@voidlinux","subject":"Re: [PATCH] Allow use of TLS 1.3","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2018-03-23T23:37:07Z","receivedAt":"2018-03-23T23:37:17Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi,\n\nOn Fri, 23 Mar 2018, Loganaden Velvindron wrote:\n\n> On Fri, Mar 23, 2018 at 07:37:08PM +0100, Ævar Arnfjörð Bjarmason wrote:\n> > \n> > On Fri, Mar 23 2018, Loganaden Velvindron wrote:\n> > \n> > > Done during IETF 101 hackathon\n> > \n> > Hi. Thanks. Let's add a meaningful commit message to this though,\n> > something like:\n> > \n> >     Add a tlsv1.3 option to http.sslVersion in addition to the existing\n> >     tlsv1.[012] options. libcurl has supported this since 7.52.0.\n\nCan we please also add that OpenSSL 1.1.* is required (or that cURL is\nbuilt with NSS or BoringSSL as the TLS backend)?\n\nThanks,\nJohannes"}]}