git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: http.sslVersion only specifies minimum TLS version, later versions are allowed

From
Daniel Stenberg <daniel@haxx.se>
Date
May 3, 2021, 21:09 UTC
Message-ID
<nycvar.QRO.7.76.2105032306580.30150@fvyyl>
In-Reply-To
<000c01d7405f$823fd090$86bf71b0$@nexbridge.com>
On Mon, 3 May 2021, Randall S. Becker wrote:
> What if http.sslVersion=v1[,v2]... were supported, so there would be an 
> enumeration of allowed versions.
That doesn't map very well to the options libcurl provide.
> The benefit of an enumeration is that you could force something like 
> 3.0-fips if your environment requires a FIPS-certified version for 
> communication. Admittedly this is a different use case than discussed above.

Yes, and as "3.0-fips" is not a TLS version at all I think it would complicate matters in a wrong direction.

You can build libcurl to use use a FIPS compatible crypto library today, but if you do then you still select TLS version using the same options like before.

-- 
  / daniel.haxx.se
Previous: Randall S. BeckerNext: Randall S. Becker
Message 7 of 9 in “http.sslVersion only specifies minimum TLS version, later versions are allowed”
  1. Daniel CarpenterMay 3, 2021
  2. Ævar Arnfjörð BjarmasonMay 3, 2021
  3. Jeff KingMay 3, 2021
  4. Daniel CarpenterMay 3, 2021
  5. Jeff KingMay 3, 2021
  6. Randall S. BeckerMay 3, 2021
  7. Daniel StenbergMay 3, 2021
  8. Randall S. BeckerMay 3, 2021
  9. Daniel StenbergMay 3, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.