git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: http.sslVersion only specifies minimum TLS version, later versions are allowed

From
Daniel Stenberg <daniel@haxx.se>
Date
May 3, 2021, 20:56 UTC
Message-ID
<nycvar.QRO.7.76.2105032250540.30150@fvyyl>
In-Reply-To
<YJBhH0eLKRSpPFy3@coredump.intra.peff.net>
On Mon, 3 May 2021, Jeff King wrote:
> I think it would also make sense to improve the documentation for 
> http.sslVersion to make it clear that this is a minimum (the current wording 
> is quite misleading).

While improving the http.sslVersion, maybe also consider dropping the special mention of NSS and OpenSSL in there? Maybe just like this:

         The SSL version to use when negotiating an SSL connection, if you
         want to force the default.  The available and default version
-       depend on whether libcurl was built against NSS or OpenSSL and the
-       particular configuration of the crypto library in use. Internally
+       depend on which TLS library libcurl was built to use. Internally
         this sets the 'CURLOPT_SSL_VERSION' option; see the libcurl
         documentation for more details on the format of this option and
         for the ssl version supported. Currently the possible values of

Maybe also consider dropping 'sslv2' and 'sslv3' from the docs now since virtually no TLS library supports them since several years now (as they're considered insecure and bad) and therefor asking curl to use those will more often than not rather cause an error.

-- 
  / daniel.haxx.se
Previous: Randall S. Becker
Message 9 of 9 in “http.sslVersion only specifies minimum TLS version, later versions are allowed”
  1. Daniel CarpenterMay 3, 2021
  2. Ævar Arnfjörð BjarmasonMay 3, 2021
  3. Jeff KingMay 3, 2021
  4. Daniel CarpenterMay 3, 2021
  5. Jeff KingMay 3, 2021
  6. Randall S. BeckerMay 3, 2021
  7. Daniel StenbergMay 3, 2021
  8. Randall S. BeckerMay 3, 2021
  9. Daniel StenbergMay 3, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.