git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [REGRESSION] Can't clone GitHub repos (fetch-pack error) due to avoiding deprecated OpenSSL SHA-1 routines

From
Bagas Sanjaya <bagasdotme@gmail.com>
Date
Sep 1, 2023, 11:09 UTC
Message-ID
<ZPHGX4Dd0Mc1VVAQ@debian.me>
In-Reply-To
<ZPEf8kbBUFqLO25W@tapette.crustytoothpaste.net>
On Thu, Aug 31, 2023 at 11:19:14PM +0000, brian m. carlson wrote:
Show 14 quoted lines
> On 2023-08-31 at 12:47:19, Bagas Sanjaya wrote:
> > Hi,
> > 
> > I built Git v2.42.0 on Debian testing, linked with OpenSSL (v3.0.10 from
> > distribution) with Makefile knob `OPENSSL_SHA1=YesPlease 
> > OPENSSL_SHA256=YesPlease`. I tried to shallow clone git.git repository:
> 
> I should point out that using OpenSSL's SHA-1 support is insecure
> because it doesn't check for collisions.  As a practical matter, no
> distro builds that way, and if you distributed that build, it would
> probably qualify for a CVE.
> 
> However, OPENSSL_SHA256 being set is fine for a local build or a build
> where you're not distributing OpenSSL itself.

Thanks for the disclaimer. I did such build for myself since the distro version always lagging.

-- 
An old man doll... just what I always wanted! - Clara
Previous: Bagas Sanjaya
Message 8 of 8 in “[REGRESSION] Can't clone GitHub repos (fetch-pack error) due to avoiding deprecated OpenSSL SHA-1 routines”
  1. Bagas SanjayaAug 31, 2023
  2. brian m. carlsonAug 31, 2023
  3. Eric WongSep 1, 2023
  4. treewide: fix various bugs w/ OpenSSL 3+ EVP APIEric Wong, Sep 1, 2023
  5. Junio C HamanoSep 1, 2023
  6. Oswald BuddenhagenSep 1, 2023
  7. Bagas SanjayaSep 1, 2023
  8. Bagas SanjayaSep 1, 2023

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.