git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is set

From
Junio C Hamano <gitster@pobox.com>
Date
Feb 21, 2008, 23:10 UTC
Message-ID
<7vd4qpsy6q.fsf@gitster.siamese.dyndns.org>
In-Reply-To
<1203621790-1415-1-git-send-email-mh@glandium.org>
Mike Hommey <mh@glandium.org> writes:
Show 17 quoted lines
> Signed-off-by: Mike Hommey <mh@glandium.org>
> ---
>  http.c |    1 +
>  1 files changed, 1 insertions(+), 0 deletions(-)
>
> diff --git a/http.c b/http.c
> index 5925d07..519621a 100644
> --- a/http.c
> +++ b/http.c
> @@ -177,6 +177,7 @@ static CURL* get_curl_handle(void)
>  	CURL* result = curl_easy_init();
>  
>  	curl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);
> +	curl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, curl_ssl_verify * 2);
>  #if LIBCURL_VERSION_NUM >= 0x070907
>  	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
>  #endif
Is it just me who finds that "* 2" is extremely magical?
diff --git a/http.c b/http.c
index 5925d07..8dce820 100644
--- a/http.c
+++ b/http.c
@@ -176,7 +176,16 @@ static CURL* get_curl_handle(void)
 {
 	CURL* result = curl_easy_init();
 
-	curl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, curl_ssl_verify);
+	if (!curl_ssl_verify) {
+		curl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, 0);
+		curl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 0);
+	} else {
+		/* Verify authenticity of the peer's certificate */
+		curl_easy_setopt(result, CURLOPT_SSL_VERIFYPEER, 1);
+		/* The name in the cert must match whom we tried to connect */
+		curl_easy_setopt(result, CURLOPT_SSL_VERIFYHOST, 2);
+	}
+
 #if LIBCURL_VERSION_NUM >= 0x070907
 	curl_easy_setopt(result, CURLOPT_NETRC, CURL_NETRC_OPTIONAL);
 #endif
Previous: Mike HommeyNext: Mike Hommey
Message 6 of 9 in “GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate”
  1. Anatoly YakovenkoFeb 20, 2008
  2. Mike HommeyFeb 21, 2008
  3. Anatoly YakovenkoFeb 21, 2008
  4. Daniel StenbergFeb 21, 2008
  5. Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is setMike Hommey, Feb 21, 2008
  6. Junio C HamanoFeb 21, 2008
  7. Mike HommeyFeb 21, 2008
  8. Anatoly YakovenkoFeb 22, 2008
  9. Daniel StenbergFeb 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.