git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v6] http: add http.sslVerifyStatus to check stapled OCSP responses

From
GGGrayson Gordon <graysongordon1@gmail.com>
Date
Aug 28, 2026, 13:51 UTC
Message-ID
<CALgUfNjd_y-e-zTKJ31o8_bQuRw8wFWe=sdsf2KJ7LOmmO21aQ@mail.gmail.com>
In-Reply-To
<xmqqpkz4czhu.fsf@gitster.g>
Junio,

Yes, I was hoping for clarity on how thorough we wanted the testing to be. Patrick added a lot of great stuff that I’m happy to use if that’s your preference, but we also talked about wanting to keep the tests succinct. Please let me know what you feel is most appropriate.

- Grayson
On Wed, Aug 26, 2026 at 6:01 PM Junio C Hamano <gitster@pobox.com> wrote:
Show 55 quoted lines
>
> graysongordon-gl <graysongordon1@gmail.com> writes:
>
> > From: Grayson Gordon <graysongordon1@gmail.com>
> >
> > git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the
> > OCSP "Certificate Status Request" extension and any stapled response a
> > server sends is ignored, including responses that explicitly state the
> > certificate has been revoked.
> >
> > Add an http.sslVerifyStatus boolean that maps to
> > CURLOPT_SSL_VERIFYSTATUS.
> > http_options() is already the collect_fn for a urlmatch config, so the
> > per-URL form works with no changes:
> >
> >     git config http.https://example.com/.sslVerifyStatus true
> >
> > Defaults to false/"off". This is due to the nature of the OCSP protocol.
> > If enabled, git would expect to receive OCSP stapled responses. If the
> > stapled responses were not present, the connection would be blocked as
> > the status of the server's certificate could not be verified. This would
> > break connections to legitimate services that don't use OCSP as their
> > certificate revocation mechanism.
> >
> > If the backend can't check the staple, curl_easy_setopt() returns
> > CURLE_NOT_BUILT_IN. Error message includes curl_easy_strerror() with
> > the option name to enable users to more easily identify a libcurl
> > built without status verification.
> >
> > CURLOPT_SSL_VERIFYSTATUS has existed since libcurl 7.41.0, below our
> > 7.61.0 floor, so no version guard is needed.
> >
> > Tests are in t5551.
> >
> > Additional note - I put this in http.adoc:
> > "Defaults to false, which
> > allows connections to remotes without validating whether or not
> > the certificate has been revoked by the certificate authority."
> >
> > Technically, there are cases with older combinations of GnuTLS
> > and curl where the revocation logic actually WILL NOT allow
> > such connections. Search "OCSP" in the lore for full details.
> >
> > Signed-off-by: Grayson Gordon <graysongordon1@gmail.com>
> > ---
> >  Documentation/config/http.adoc | 14 ++++++++++++++
> >  http.c                         | 14 ++++++++++++++
> >  t/t5551-http-fetch-smart.sh    | 29 +++++++++++++++++++++++++++++
> >  3 files changed, 57 insertions(+)
>
> Are folks happy with this iteration?  I think we have already
> reached the point of diminishing returns before the thread went
> dark.
>
> Thanks.
Previous: Junio C HamanoNext: Junio C Hamano
Message 21 of 40 in “http: add http.sslVerifyStatus to check stapled OCSP responses”
  1. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  2. Junio C HamanoAug 11, 2026
  3. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  4. Patrick SteinhardtAug 12, 2026
  5. Grayson GordonAug 12, 2026
  6. Junio C HamanoAug 12, 2026
  7. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 12, 2026
  8. Junio C HamanoAug 12, 2026
  9. Junio C HamanoAug 13, 2026
  10. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 17, 2026
  11. Junio C HamanoAug 17, 2026
  12. Patrick SteinhardtAug 18, 2026
  13. Grayson GordonAug 18, 2026
  14. Patrick SteinhardtAug 19, 2026
  15. Junio C HamanoAug 18, 2026
  16. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  17. Junio C HamanoAug 18, 2026
  18. Grayson GordonAug 18, 2026
  19. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  20. Junio C HamanoAug 26, 2026
  21. Grayson GordonAug 28, 2026
  22. Junio C HamanoAug 28, 2026
  23. Patrick SteinhardtAug 31, 2026
  24. Junio C HamanoAug 31, 2026
  25. Patrick SteinhardtAug 31, 2026
  26. Junio C HamanoAug 31, 2026
  27. Grayson GordonSep 8, 2026
  28. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Sep 15, 2026
  29. Junio C HamanoSep 16, 2026
  30. Patrick SteinhardtSep 23, 2026
  31. Junio C HamanoSep 23, 2026
  32. SZEDER GáborSep 23, 2026
  33. Junio C HamanoSep 23, 2026
  34. SZEDER GáborSep 24, 2026
  35. Patrick SteinhardtSep 24, 2026
  36. SZEDER GáborSep 25, 2026
  37. Junio C HamanoSep 25, 2026
  38. Junio C HamanoSep 24, 2026
  39. Junio C HamanoOct 7, 2026
  40. Junio C HamanoOct 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.