git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate

From
Anatoly Yakovenko <aeyakovenko@gmail.com>
Date
Feb 22, 2008, 01:27 UTC
Message-ID
<e26d18e40802211727w4f7f5b37vc73a756f6b384289@mail.gmail.com>
In-Reply-To
<20080221190954.GA24759@glandium.org>
On Thu, Feb 21, 2008 at 11:09 AM, Mike Hommey <mh@glandium.org> wrote:
Show 7 quoted lines
> On Thu, Feb 21, 2008 at 10:57:58AM -0800, Anatoly Yakovenko wrote:
>  > yep, it tells me that the certificate is rejected because it was
>  > signed for a different ip then the one i am connected too.  while this
>  > is a security threat, browsers will let you ignore it, so i expect
>  > that libcurl or git should be able to ignore that error as well.
>
>  What is the exact message ?

$ GIT_SSL_NO_VERIFY=1 GIT_CURL_VERBOSE=1 git clone https://aeyakovenko@127.0.0.1/git

i get this as an error:

error: SSL: certificate subject name 'localhost' does not match target host name '127.0.0.1' (curl_result = 51, http_code = 0, sha1 = 4590de71622f1a90f906413fd7f63d5553cd5f93)

cloning https://aeyakovenko@localhost/git works fine
Previous: Mike HommeyNext: Daniel Stenberg
Message 8 of 9 in “GIT_SSL_NO_VERIFY=1 over http doesn't ignore a different ip address for the signed certificate”
  1. Anatoly YakovenkoFeb 20, 2008
  2. Mike HommeyFeb 21, 2008
  3. Anatoly YakovenkoFeb 21, 2008
  4. Daniel StenbergFeb 21, 2008
  5. Don't verify host name in SSL certs when GIT_SSL_NO_VERIFY is setMike Hommey, Feb 21, 2008
  6. Junio C HamanoFeb 21, 2008
  7. Mike HommeyFeb 21, 2008
  8. Anatoly YakovenkoFeb 22, 2008
  9. Daniel StenbergFeb 22, 2008

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.