git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SNI (SSL virtual hosts)

From
JHJanusz Harkot <janusz.harkot@gmail.com>
Date
Jun 4, 2013, 10:19 UTC
Message-ID
<8B7A2C3A8CC346D6B34D153F591F878F@gmail.com>
In-Reply-To
<alpine.DEB.2.00.1306041142200.16303@tvnag.unkk.fr>
> It does. git uses libcurl for the HTTPS parts and it has support SNI for a 
> long time, assuming you built libcurl with a TLS library that handles it.
> 
> Which libcurl version and SSL backend is this? (curl -V usually tells)
$ curl -V
curl 7.24.0 (x86_64-apple-darwin12.0) libcurl/7.24.0 OpenSSL/0.9.8r zlib/1.2.5
Protocols: dict file ftp ftps gopher http https imap imaps ldap ldaps pop3 pop3s rtsp smtp smtps telnet tftp 
Features: AsynchDNS GSS-Negotiate IPv6 Largefile NTLM NTLM_WB SSL libz 

$ otool -L /usr/local/bin/git /usr/local/bin/git: /usr/lib/libz.1.dylib (compatibility version 1.0.0, current version 1.2.5) /usr/lib/libiconv.2.dylib (compatibility version 7.0.0, current version 7.0.0) /usr/local/opt/openssl/lib/libcrypto.1.0.0.dylib (compatibility version 1.0.0, current version 1.0.0) /usr/local/opt/openssl/lib/libssl.1.0.0.dylib (compatibility version 1.0.0, current version 1.0.0) /usr/lib/libSystem.B.dylib (compatibility version 1.0.0, current version 169.3.0)

> If you made it working by disabling certificate verification then it sounds as 
> if SNI might still have worked and the problem was rahter something else, as 
> without SNI you can't do name-based virtual hosting over HTTPS - but perhaps 
> you wanted to communicate with the "default" server on that IP?
here is a log (with GIT_CURL_VERBOSE=1)
https://gist.github.com/anonymous/8f6533a755ae5c710c75 
Initial connection is correct (line 10 - shows that it reads correct certificate),
 but then subsequent call to the server (line 68) shows that the defat server certificate is used.
It looks like the second call was without hostname (?).

Thanks! Janusz

Previous: Daniel StenbergNext: Daniel Stenberg
Message 3 of 8 in “SNI (SSL virtual hosts)”
  1. Janusz HarkotJun 4, 2013
  2. Daniel StenbergJun 4, 2013
  3. Janusz HarkotJun 4, 2013
  4. Daniel StenbergJun 4, 2013
  5. Janusz HarkotJun 4, 2013
  6. Daniel StenbergJun 4, 2013
  7. Janusz HarkotJun 4, 2013
  8. Daniel StenbergJun 5, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.