git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: SNI (SSL virtual hosts)

From
Daniel Stenberg <daniel@haxx.se>
Date
Jun 4, 2013, 09:45 UTC
Message-ID
<alpine.DEB.2.00.1306041142200.16303@tvnag.unkk.fr>
In-Reply-To
<97F8F367D27D4B3E93439FF8D0F121FA@gmail.com>
On Tue, 4 Jun 2013, Janusz Harkot wrote:
Show 6 quoted lines
> Strange was, that initial communication was OK (http GET), but when there 
> was http POST - git reported error (incorrect certificate). The only 
> workaround was to disable certificate verification.
>
> My question is: does git support SNI on the https? If so - are there 
> (undocumented) options to make it work?

It does. git uses libcurl for the HTTPS parts and it has support SNI for a long time, assuming you built libcurl with a TLS library that handles it.

Which libcurl version and SSL backend is this? (curl -V usually tells)

If you made it working by disabling certificate verification then it sounds as if SNI might still have worked and the problem was rahter something else, as without SNI you can't do name-based virtual hosting over HTTPS - but perhaps you wanted to communicate with the "default" server on that IP?

-- 
  / daniel.haxx.se
Previous: Janusz HarkotNext: Janusz Harkot
Message 2 of 8 in “SNI (SSL virtual hosts)”
  1. Janusz HarkotJun 4, 2013
  2. Daniel StenbergJun 4, 2013
  3. Janusz HarkotJun 4, 2013
  4. Daniel StenbergJun 4, 2013
  5. Janusz HarkotJun 4, 2013
  6. Daniel StenbergJun 4, 2013
  7. Janusz HarkotJun 4, 2013
  8. Daniel StenbergJun 5, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.