git/list[1] front-page[2] threads[3] people[4] search[5] about
 

http.sslVersion only specifies minimum TLS version, later versions are allowed

From
DCDaniel Carpenter <dc@ammonit.com>
Date
May 3, 2021, 11:56 UTC
Message-ID
<8f664b07d1df45bcb6b3f787f42bd046@ammonit.com>
When I run: "GIT_SSL_VERSION=tlsv1.2 GIT_CURL_VERBOSE=T git clone https://github.com/git/git.git"
I see: "SSL connection using TLS1.3 / ECDHE_RSA_AES_128_GCM_SHA256", but I was expecting to see "TLS1.2".
This happens because the "sslversions" array ( https://github.com/git/git/blob/7e391989789db82983665667013a46eabc6fc570/http.c#L58 ) uses "CURL_SSLVERSION_TLSv1_2" which only specifies TLS 1.2 or later ( https://curl.se/libcurl/c/CURLOPT_SSLVERSION.html ).
I think configuring "tlsv1.2" should imply "CURL_SSLVERSION_TLSv1_2 | CURL_SSLVERSION_MAX_TLSv1_2", to force that specific version (and the same for "tlsv1.0", "tlsv1.1", "tlsv1.3").
For background: I noticed this because of this issue with debian buster https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987188 . The new libcurl backport enables TLS 1.3 support with gnutls, but it doesn't work for certain operations, so buster applications using a backported libcurl need to explicitly disable TLS 1.3 .
Next: Ævar Arnfjörð Bjarmason
Message 1 of 9 in “http.sslVersion only specifies minimum TLS version, later versions are allowed”
  1. Daniel CarpenterMay 3, 2021
  2. Ævar Arnfjörð BjarmasonMay 3, 2021
  3. Jeff KingMay 3, 2021
  4. Daniel CarpenterMay 3, 2021
  5. Jeff KingMay 3, 2021
  6. Randall S. BeckerMay 3, 2021
  7. Daniel StenbergMay 3, 2021
  8. Randall S. BeckerMay 3, 2021
  9. Daniel StenbergMay 3, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.