git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v6] http: add http.sslVerifyStatus to check stapled OCSP responses

From
Patrick Steinhardt <ps@pks.im>
Date
Aug 31, 2026, 06:56 UTC
Message-ID
<apUlqvXgChMeCUkp@pks.im>
In-Reply-To
<xmqqld9q40ww.fsf@gitster.g>
On Fri, Aug 28, 2026 at 10:20:31AM -0700, Junio C Hamano wrote:
Show 13 quoted lines
> Grayson Gordon <graysongordon1@gmail.com> writes:
> 
> > Junio,
> >
> > Yes, I was hoping for clarity on how thorough we wanted the testing to
> > be. Patrick added a lot of great stuff that I’m happy to use if that’s
> > your preference, but we also talked about wanting to keep the tests
> > succinct. Please let me know what you feel is most appropriate.
> 
> If you can keep them succinct but still test the essential bits,
> that would be great, but I am not sure if that is a great question
> to ask me ;-)  Patrick?  You said "not 100% sure given the complexity",
> but which parts make you feel iffy? 

Setting up OCSP is quite a pain, and that is what made me feel iffy. That being said, given that this is a security-focussed feature I feel like we should probably bite the bullet and verify that we indeed know to reject servers that respond with invalid stapled responses.

And given that this whole setup is now getting more complex I feel like it's worth it to also allocate a new test number for it.

> They do look involved but seem to cover the situations we do care
> about, except we seem not to test when the server does not explicitly
> say "this is still good", or am I not reading the tests correctly?
Isn't the following test covering that scenario? Or am I misreading?
    test_expect_success SSL_VERIFYSTATUS 'fetch succeeds with stapled "good" OCSP response'
           with_ssl_verification git -c http.sslVerifyStatus=true \
                   ls-remote "$HTTPD_URL/smart/repo.git" >actual &&
           test_line_count -gt 0 actual
    '
Thanks!
Patrick
Previous: Junio C HamanoNext: Junio C Hamano
Message 23 of 39 in “http: add http.sslVerifyStatus to check stapled OCSP responses”
  1. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  2. Junio C HamanoAug 11, 2026
  3. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  4. Patrick SteinhardtAug 12, 2026
  5. Grayson GordonAug 12, 2026
  6. Junio C HamanoAug 12, 2026
  7. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 12, 2026
  8. Junio C HamanoAug 12, 2026
  9. Junio C HamanoAug 13, 2026
  10. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 17, 2026
  11. Junio C HamanoAug 17, 2026
  12. Patrick SteinhardtAug 18, 2026
  13. Grayson GordonAug 18, 2026
  14. Patrick SteinhardtAug 19, 2026
  15. Junio C HamanoAug 18, 2026
  16. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  17. Junio C HamanoAug 18, 2026
  18. Grayson GordonAug 18, 2026
  19. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  20. Junio C HamanoAug 26, 2026
  21. Grayson GordonAug 28, 2026
  22. Junio C HamanoAug 28, 2026
  23. Patrick SteinhardtAug 31, 2026
  24. Junio C HamanoAug 31, 2026
  25. Patrick SteinhardtAug 31, 2026
  26. Junio C HamanoAug 31, 2026
  27. Grayson GordonSep 8, 2026
  28. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Sep 15, 2026
  29. Junio C HamanoSep 16, 2026
  30. Patrick SteinhardtSep 23, 2026
  31. Junio C HamanoSep 23, 2026
  32. SZEDER GáborSep 23, 2026
  33. Junio C HamanoSep 23, 2026
  34. SZEDER GáborSep 24, 2026
  35. Patrick SteinhardtSep 24, 2026
  36. SZEDER GáborSep 25, 2026
  37. Junio C HamanoSep 25, 2026
  38. Junio C HamanoSep 24, 2026
  39. Junio C HamanoOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.