{"thread":{"id":"48149","subject":"[PATCH v3] Allow use of TLS 1.3","startedAt":"2018-03-26T09:27:15Z","lastAt":"2018-03-26T21:46:56Z","messageCount":3,"participants":["Loganaden Velvindron","Johannes Schindelin","Daniel Stenberg"],"isPatch":true,"patchVersion":3,"patchTotal":null},"messages":[{"id":"342982","messageId":"20180326092423.GA7521@voidlinux","threadId":"48149","inReplyTo":null,"subject":"[PATCH v3] Allow use of TLS 1.3","fromName":"Loganaden Velvindron","fromEmail":"logan@hackers.mu","sentAt":"2018-03-26T09:24:23Z","receivedAt":"2018-03-26T09:27:15Z","isPatch":true,"sender":{"key":"logan@hackers.mu","avatar":"https://avatars.githubusercontent.com/u/1688420?v=4"},"body":"Add a tlsv1.3 option to http.sslVersion in addition to the existing\ntlsv1.[012] options. libcurl has supported this since 7.52.0.\n\nSigned-off-by: Loganaden Velvindron <logan@hackers.mu>\n---\n Documentation/config.txt | 1 +\n http.c                   | 3 +++\n 2 files changed, 4 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex ce9102cea..f31d62772 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1957,6 +1957,7 @@ http.sslVersion::\n \t- tlsv1.0\n \t- tlsv1.1\n \t- tlsv1.2\n+\t- tlsv1.3\n \n +\n Can be overridden by the `GIT_SSL_VERSION` environment variable.\ndiff --git a/http.c b/http.c\nindex a5bd5d62c..f84b18551 100644\n--- a/http.c\n+++ b/http.c\n@@ -62,6 +62,9 @@ static struct {\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n+#endif\n };\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-- \n2.16.2\n\n"},{"id":"343072","messageId":"nycvar.QRO.7.76.6.1803262336070.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz","threadId":"48149","inReplyTo":"20180326092423.GA7521@voidlinux","subject":"Re: [PATCH v3] Allow use of TLS 1.3","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2018-03-26T21:38:17Z","receivedAt":"2018-03-26T21:38:24Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Logan,\n\nOn Mon, 26 Mar 2018, Loganaden Velvindron wrote:\n\n> Add a tlsv1.3 option to http.sslVersion in addition to the existing\n> tlsv1.[012] options. libcurl has supported this since 7.52.0.\n> \n> Signed-off-by: Loganaden Velvindron <logan@hackers.mu>\n\nCan we *please* also add that OpenSSL 1.1.* is required (or that cURL is\nbuilt with NSS or BoringSSL as the TLS backend)?\n\nSee\nhttps://public-inbox.org/git/nycvar.QRO.7.76.6.1803240035300.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz/\nfor my original please.\n\nI deem this information *really* important because a lot of Git packages\nare still built against OpenSSL 1.0.2 (e.g. Git for Windows) and *won't*\nbenefit immediately from your patch.\n\nCiao,\nJohannes\n"},{"id":"343075","messageId":"alpine.DEB.2.20.1803262340320.25724@tvnag.unkk.fr","threadId":"48149","inReplyTo":"nycvar.QRO.7.76.6.1803262336070.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz","subject":"Re: [PATCH v3] Allow use of TLS 1.3","fromName":"Daniel Stenberg","fromEmail":"daniel@haxx.se","sentAt":"2018-03-26T21:46:45Z","receivedAt":"2018-03-26T21:46:56Z","isPatch":true,"sender":{"key":"daniel@haxx.se","avatar":"https://gravatar.com/avatar/69fdca87edd17cee21ca2e79fc2ff671d644603c3dc27167430f3cd3dbab7ba8?d=mp&s=160"},"body":"On Mon, 26 Mar 2018, Johannes Schindelin wrote:\n\n> Can we *please* also add that OpenSSL 1.1.* is required (or that cURL is \n> built with NSS or BoringSSL as the TLS backend)?\n\nWe might consider adding a way to extract that info from curl to make that \nwork really good for you. There are now six TLS libraries that support TLS 1.3 \nand it might be hard for git to figure out the exact situation for each \nlibrary and keep track of these moving targets...\n\n-- \n\n  / daniel.haxx.se\n"}]}