Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
- From
Patrick Steinhardt <ps@pks.im>
- Date
- Sep 23, 2026, 12:42 UTC
- Message-ID
- <arPI8PfvsKUJSypg@pks.im>
- In-Reply-To
- <20260915162348.97792-1-ggordon@gitlab.com>
On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote:
Show 24 quoted lines
> From: Grayson Gordon <graysongordon1@gmail.com> > > git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the > OCSP "Certificate Status Request" extension and any stapled response a > server sends is ignored, including responses that explicitly state the > certificate has been revoked. > > Add an http.sslVerifyStatus boolean that maps to > CURLOPT_SSL_VERIFYSTATUS. http_options() is already the collect_fn for a > urlmatch config, so the per-URL form works with no changes: > > git config http.https://example.com/.sslVerifyStatus true > > Defaults to false/"off". This is due to the nature of the OCSP protocol. > If enabled, git would expect to receive OCSP stapled responses. If the > stapled responses were not present, the connection would be blocked as > the status of the server's certificate could not be verified. This would > break connections to legitimate services that don't use OCSP as their > certificate revocation mechanism. > > If the backend can't check the staple, curl_easy_setopt() returns > CURLE_NOT_BUILT_IN. The error message includes curl_easy_strerror() > along with the option name, so a libcurl built without status > verification is easy to identify.
Nit: I feel like this paragraph is excessive information, as it doesn't give the reviewer any additional context over what the code already states.
Show 9 quoted lines
> CURLOPT_SSL_VERIFYSTATUS has existed since libcurl 7.41.0, below our > 7.61.0 floor, so no version guard is needed. > > The tests that need no OCSP infrastructure stay in t5551, which t5559 > runs over https. The rest need a certificate authority, a responder to > answer for it and a server configured to staple, so lib-httpd gains an > opt-in LIB_HTTPD_OCSP mode and t5585 uses it to check that a "good" > staple is accepted, a "revoked" one is refused, and that the revoked one > is ignored when the option is off.
Nit: Likewise, this paragraph doesn't add much value.
Other than that I'm happy with this patch. I'll leave it to you (or others) to decide whether this requires another reroll to address the two nits.
Thanks!
Patrick