git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses

From
SZEDER Gábor <szeder.dev@gmail.com>
Date
Sep 25, 2026, 09:28 UTC
Message-ID
<arY+2p3YZWlyL9Gq@szeder.dev>
In-Reply-To
<arTYVLnW-2GHpGGm@pks.im>
On Thu, Sep 24, 2026 at 09:59:16AM +0200, Patrick Steinhardt wrote:
Show 29 quoted lines
> On Thu, Sep 24, 2026 at 09:41:41AM +0200, SZEDER Gábor wrote:
> > On Wed, Sep 23, 2026 at 02:47:18PM -0700, Junio C Hamano wrote:
> > > SZEDER Gábor <szeder.dev@gmail.com> writes:
> > > 
> > > > On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote:
> > > >> From: Grayson Gordon <graysongordon1@gmail.com>
> > > >> 
> > > >> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the
> > > >> OCSP "Certificate Status Request" extension and any stapled response a
> > > >> server sends is ignored, including responses that explicitly state the
> > > >> certificate has been revoked.
> > > > ...
> > > > This patch was merged to 'next' the other day, and the last test in
> > > > the new t5585 fails on my system.
> > > 
> > > Sorry about a premature merge.  Since we are not in a hurry to take
> > > this topic in (or no new feature topic in general), let me revert it
> > > out of 'next' and give it a clean slate to try again.
> > 
> > Well, if you hadn't merged it, we would perhaps still be none the
> > wiser, because, alas, I don't have the bandwidth to run tests on the
> > seen branch regularly...
> > 
> > However, CI does, but I can't seem to find any CI runs that failed
> > because of this, which makes me worried that something is wrong on my
> > end.
> 
> Do you maybe run with a curl backend that doesn't properly support OCSP?
> But even if so, our test suite should notice and skip the tests.

Apparently I did! Removing 'libcurl4-gnutls-dev' and installing 'libcurl4-openssl-dev' instead makes t5585 succeed. Go figure.

Thanks for the hint!
Previous: Patrick SteinhardtNext: Junio C Hamano
Message 36 of 40 in “http: add http.sslVerifyStatus to check stapled OCSP responses”
  1. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  2. Junio C HamanoAug 11, 2026
  3. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  4. Patrick SteinhardtAug 12, 2026
  5. Grayson GordonAug 12, 2026
  6. Junio C HamanoAug 12, 2026
  7. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 12, 2026
  8. Junio C HamanoAug 12, 2026
  9. Junio C HamanoAug 13, 2026
  10. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 17, 2026
  11. Junio C HamanoAug 17, 2026
  12. Patrick SteinhardtAug 18, 2026
  13. Grayson GordonAug 18, 2026
  14. Patrick SteinhardtAug 19, 2026
  15. Junio C HamanoAug 18, 2026
  16. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  17. Junio C HamanoAug 18, 2026
  18. Grayson GordonAug 18, 2026
  19. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  20. Junio C HamanoAug 26, 2026
  21. Grayson GordonAug 28, 2026
  22. Junio C HamanoAug 28, 2026
  23. Patrick SteinhardtAug 31, 2026
  24. Junio C HamanoAug 31, 2026
  25. Patrick SteinhardtAug 31, 2026
  26. Junio C HamanoAug 31, 2026
  27. Grayson GordonSep 8, 2026
  28. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Sep 15, 2026
  29. Junio C HamanoSep 16, 2026
  30. Patrick SteinhardtSep 23, 2026
  31. Junio C HamanoSep 23, 2026
  32. SZEDER GáborSep 23, 2026
  33. Junio C HamanoSep 23, 2026
  34. SZEDER GáborSep 24, 2026
  35. Patrick SteinhardtSep 24, 2026
  36. SZEDER GáborSep 25, 2026
  37. Junio C HamanoSep 25, 2026
  38. Junio C HamanoSep 24, 2026
  39. Junio C HamanoOct 7, 2026
  40. Junio C HamanoOct 8, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.