git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v6] http: add http.sslVerifyStatus to check stapled OCSP responses

From
Junio C Hamano <gitster@pobox.com>
Date
Aug 31, 2026, 14:31 UTC
Message-ID
<xmqqecfez7ie.fsf@gitster.g>
In-Reply-To
<apWOuGbOErZt9jo8@pks.im>
Patrick Steinhardt <ps@pks.im> writes:
Show 23 quoted lines
> On Mon, Aug 31, 2026 at 07:16:54AM -0700, Junio C Hamano wrote:
>> Patrick Steinhardt <ps@pks.im> writes:
>> 
>> >> They do look involved but seem to cover the situations we do care
>> >> about, except we seem not to test when the server does not explicitly
>> >> say "this is still good", or am I not reading the tests correctly?
>> >
>> > Isn't the following test covering that scenario? Or am I misreading?
>> >
>> >     test_expect_success SSL_VERIFYSTATUS 'fetch succeeds with stapled "good" OCSP response'
>> >            with_ssl_verification git -c http.sslVerifyStatus=true \
>> >                    ls-remote "$HTTPD_URL/smart/repo.git" >actual &&
>> >            test_line_count -gt 0 actual
>> >     '
>> 
>> Probably I misstated.  What I meant was a reaction to "fail close"
>> floated earlier.  A server does not explicitly give stapled good,
>> and the client says "this is not known-good" and not talking to it.
>> I.e. 'fetch fails without stapled "good"'
>
> Ah, I think you're correct, my tests didn't include that. But Grayson's
> already did as it doesn't require any setup, so that's why I didn't
> include it specifically.

Ah, I missed that. So a combined patch taking the best parts from both sides is what we want. Thanks for helping move the topic forward.

Previous: Patrick SteinhardtNext: Grayson Gordon
Message 26 of 39 in “http: add http.sslVerifyStatus to check stapled OCSP responses”
  1. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  2. Junio C HamanoAug 11, 2026
  3. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 11, 2026
  4. Patrick SteinhardtAug 12, 2026
  5. Grayson GordonAug 12, 2026
  6. Junio C HamanoAug 12, 2026
  7. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 12, 2026
  8. Junio C HamanoAug 12, 2026
  9. Junio C HamanoAug 13, 2026
  10. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 17, 2026
  11. Junio C HamanoAug 17, 2026
  12. Patrick SteinhardtAug 18, 2026
  13. Grayson GordonAug 18, 2026
  14. Patrick SteinhardtAug 19, 2026
  15. Junio C HamanoAug 18, 2026
  16. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  17. Junio C HamanoAug 18, 2026
  18. Grayson GordonAug 18, 2026
  19. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Aug 18, 2026
  20. Junio C HamanoAug 26, 2026
  21. Grayson GordonAug 28, 2026
  22. Junio C HamanoAug 28, 2026
  23. Patrick SteinhardtAug 31, 2026
  24. Junio C HamanoAug 31, 2026
  25. Patrick SteinhardtAug 31, 2026
  26. Junio C HamanoAug 31, 2026
  27. Grayson GordonSep 8, 2026
  28. http: add http.sslVerifyStatus to check stapled OCSP responsesgraysongordon-gl, Sep 15, 2026
  29. Junio C HamanoSep 16, 2026
  30. Patrick SteinhardtSep 23, 2026
  31. Junio C HamanoSep 23, 2026
  32. SZEDER GáborSep 23, 2026
  33. Junio C HamanoSep 23, 2026
  34. SZEDER GáborSep 24, 2026
  35. Patrick SteinhardtSep 24, 2026
  36. SZEDER GáborSep 25, 2026
  37. Junio C HamanoSep 25, 2026
  38. Junio C HamanoSep 24, 2026
  39. Junio C HamanoOct 7, 2026

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.