{"thread":{"id":"48182","subject":"[PATCH v4] Allow use of TLS 1.3","startedAt":"2018-03-29T10:17:17Z","lastAt":"2018-03-29T20:40:29Z","messageCount":3,"participants":["Loganaden Velvindron","Johannes Schindelin","Junio C Hamano"],"isPatch":true,"patchVersion":4,"patchTotal":null},"messages":[{"id":"343313","messageId":"20180329101418.GA7736@voidlinux","threadId":"48182","inReplyTo":null,"subject":"[PATCH v4] Allow use of TLS 1.3","fromName":"Loganaden Velvindron","fromEmail":"logan@hackers.mu","sentAt":"2018-03-29T10:14:18Z","receivedAt":"2018-03-29T10:17:17Z","isPatch":true,"sender":{"key":"logan@hackers.mu","avatar":"https://avatars.githubusercontent.com/u/1688420?v=4"},"body":"Add a tlsv1.3 option to http.sslVersion in addition to the existing\ntlsv1.[012] options. libcurl has supported this since 7.52.0.\n\nThis requires OpenSSL 1.1.1 with TLS 1.3 enabled or curl built with\nrecent versions of NSS or BoringSSL as the TLS backend.\n\nSigned-off-by: Loganaden Velvindron <logan@hackers.mu>\n---\n Documentation/config.txt | 1 +\n http.c                   | 3 +++\n 2 files changed, 4 insertions(+)\n\ndiff --git a/Documentation/config.txt b/Documentation/config.txt\nindex ce9102cea..f31d62772 100644\n--- a/Documentation/config.txt\n+++ b/Documentation/config.txt\n@@ -1957,6 +1957,7 @@ http.sslVersion::\n \t- tlsv1.0\n \t- tlsv1.1\n \t- tlsv1.2\n+\t- tlsv1.3\n \n +\n Can be overridden by the `GIT_SSL_VERSION` environment variable.\ndiff --git a/http.c b/http.c\nindex a5bd5d62c..f84b18551 100644\n--- a/http.c\n+++ b/http.c\n@@ -62,6 +62,9 @@ static struct {\n \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n #endif\n+#if LIBCURL_VERSION_NUM >= 0x073400\n+\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n+#endif\n };\n #if LIBCURL_VERSION_NUM >= 0x070903\n static const char *ssl_key;\n-- \n2.16.2\n\n"},{"id":"343329","messageId":"nycvar.QRO.7.76.6.1803291702580.5026@qfpub.tvgsbejvaqbjf.bet","threadId":"48182","inReplyTo":"20180329101418.GA7736@voidlinux","subject":"Re: [PATCH v4] Allow use of TLS 1.3","fromName":"Johannes Schindelin","fromEmail":"johannes.schindelin@gmx.de","sentAt":"2018-03-29T15:03:08Z","receivedAt":"2018-03-29T15:03:17Z","isPatch":true,"sender":{"key":"johannes.schindelin@gmx.de","avatar":"https://avatars.githubusercontent.com/u/127790?v=4"},"body":"Hi Logan,\n\nOn Thu, 29 Mar 2018, Loganaden Velvindron wrote:\n\n> Add a tlsv1.3 option to http.sslVersion in addition to the existing\n> tlsv1.[012] options. libcurl has supported this since 7.52.0.\n> \n> This requires OpenSSL 1.1.1 with TLS 1.3 enabled or curl built with\n> recent versions of NSS or BoringSSL as the TLS backend.\n\nThank you,\nJohannes\n"},{"id":"343368","messageId":"xmqqd0zm62fg.fsf@gitster-ct.c.googlers.com","threadId":"48182","inReplyTo":"20180329101418.GA7736@voidlinux","subject":"Re: [PATCH v4] Allow use of TLS 1.3","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2018-03-29T20:40:19Z","receivedAt":"2018-03-29T20:40:29Z","isPatch":true,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"Loganaden Velvindron <logan@hackers.mu> writes:\n\n> diff --git a/http.c b/http.c\n> index a5bd5d62c..f84b18551 100644\n> --- a/http.c\n> +++ b/http.c\n> @@ -62,6 +62,9 @@ static struct {\n>  \t{ \"tlsv1.1\", CURL_SSLVERSION_TLSv1_1 },\n>  \t{ \"tlsv1.2\", CURL_SSLVERSION_TLSv1_2 },\n>  #endif\n> +#if LIBCURL_VERSION_NUM >= 0x073400\n> +\t{ \"tlsv1.3\", CURL_SSLVERSION_TLSv1_3 }\n\nLooks OK to me, except one minor nit.\n\nI'll add a trailing comma for this entry while queuing, so that a\nfuture patch to add tlsv1.4 or whatever won't have to worry about\nit.\n\nThanks.\n\n> +#endif\n>  };\n>  #if LIBCURL_VERSION_NUM >= 0x070903\n>  static const char *ssl_key;\n"}]}