git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate

From
Anatoly Yakovenko <aeyakovenko@gmail.com>
Date
Feb 21, 2008, 18:57 UTC
Message-ID
<e26d18e40802211057o255246f3p31800c73eb8391ec@mail.gmail.com>
In-Reply-To
<20080221064252.GA16036@glandium.org>

yep, it tells me that the certificate is rejected because it was signed for a different ip then the one i am connected too. while this is a security threat, browsers will let you ignore it, so i expect that libcurl or git should be able to ignore that error as well.

On Wed, Feb 20, 2008 at 10:42 PM, Mike Hommey <mh@glandium.org> wrote:
Show 11 quoted lines
>
> On Wed, Feb 20, 2008 at 03:35:54PM -0800, Anatoly Yakovenko wrote:
>  > I am not sure if its a bug in curl or git, but despite setting
>  > GIT_SSL_NO_VERIFY=1, if i use a different ip address or hostname then
>  > the certificate was signed for, git fails to push changes.
>
>  Can you try with GIT_CURL_VERBOSE=1 ? The trace message will probably
>  help understanding what happens.
>
>  Mike
>
Previous: Mike HommeyNext: Daniel Stenberg
Message 3 of 9 in “GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate”
  1. Anatoly YakovenkoFeb 20, 2008
  2. Mike HommeyFeb 21, 2008
  3. Anatoly YakovenkoFeb 21, 2008
  4. Daniel StenbergFeb 21, 2008
  5. Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is setMike Hommey, Feb 21, 2008
  6. Junio C HamanoFeb 21, 2008
  7. Mike HommeyFeb 21, 2008
  8. Anatoly YakovenkoFeb 22, 2008
  9. Daniel StenbergFeb 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.