Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
- From
SZEDER Gábor <szeder.dev@gmail.com>
- Date
- Sep 25, 2026, 09:28 UTC
- Message-ID
- <arY+2p3YZWlyL9Gq@szeder.dev>
- In-Reply-To
- <arTYVLnW-2GHpGGm@pks.im>
On Thu, Sep 24, 2026 at 09:59:16AM +0200, Patrick Steinhardt wrote:
Show 29 quoted lines
> On Thu, Sep 24, 2026 at 09:41:41AM +0200, SZEDER Gábor wrote: > > On Wed, Sep 23, 2026 at 02:47:18PM -0700, Junio C Hamano wrote: > > > SZEDER Gábor <szeder.dev@gmail.com> writes: > > > > > > > On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote: > > > >> From: Grayson Gordon <graysongordon1@gmail.com> > > > >> > > > >> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the > > > >> OCSP "Certificate Status Request" extension and any stapled response a > > > >> server sends is ignored, including responses that explicitly state the > > > >> certificate has been revoked. > > > > ... > > > > This patch was merged to 'next' the other day, and the last test in > > > > the new t5585 fails on my system. > > > > > > Sorry about a premature merge. Since we are not in a hurry to take > > > this topic in (or no new feature topic in general), let me revert it > > > out of 'next' and give it a clean slate to try again. > > > > Well, if you hadn't merged it, we would perhaps still be none the > > wiser, because, alas, I don't have the bandwidth to run tests on the > > seen branch regularly... > > > > However, CI does, but I can't seem to find any CI runs that failed > > because of this, which makes me worried that something is wrong on my > > end. > > Do you maybe run with a curl backend that doesn't properly support OCSP? > But even if so, our test suite should notice and skip the tests.
Apparently I did! Removing 'libcurl4-gnutls-dev' and installing 'libcurl4-openssl-dev' instead makes t5585 succeed. Go figure.
Thanks for the hint!