Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
- From
Patrick Steinhardt <ps@pks.im>
- Date
- Sep 24, 2026, 07:59 UTC
- Message-ID
- <arTYVLnW-2GHpGGm@pks.im>
- In-Reply-To
- <arTUNYVvCNwX1pDp@szeder.dev>
On Thu, Sep 24, 2026 at 09:41:41AM +0200, SZEDER Gábor wrote:
Show 25 quoted lines
> On Wed, Sep 23, 2026 at 02:47:18PM -0700, Junio C Hamano wrote: > > SZEDER Gábor <szeder.dev@gmail.com> writes: > > > > > On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote: > > >> From: Grayson Gordon <graysongordon1@gmail.com> > > >> > > >> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the > > >> OCSP "Certificate Status Request" extension and any stapled response a > > >> server sends is ignored, including responses that explicitly state the > > >> certificate has been revoked. > > > ... > > > This patch was merged to 'next' the other day, and the last test in > > > the new t5585 fails on my system. > > > > Sorry about a premature merge. Since we are not in a hurry to take > > this topic in (or no new feature topic in general), let me revert it > > out of 'next' and give it a clean slate to try again. > > Well, if you hadn't merged it, we would perhaps still be none the > wiser, because, alas, I don't have the bandwidth to run tests on the > seen branch regularly... > > However, CI does, but I can't seem to find any CI runs that failed > because of this, which makes me worried that something is wrong on my > end.
Do you maybe run with a curl backend that doesn't properly support OCSP? But even if so, our test suite should notice and skip the tests.
Patrick