Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
graysongordon-gl <graysongordon1@gmail.com> writes:
Show 28 quoted lines
> From: Grayson Gordon <graysongordon1@gmail.com>
>
> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the
> OCSP "Certificate Status Request" extension and any stapled response a
> server sends is ignored, including responses that explicitly state the
> certificate has been revoked.
>
> Add an http.sslVerifyStatus boolean that maps to
> CURLOPT_SSL_VERIFYSTATUS. http_options() is already the collect_fn for a
> urlmatch config, so the per-URL form works with no changes:
> ---
>
> Junio, Patrick: this is the combined version we discussed. The
> cases that need no OCSP setup stayed in t5551, since t5559 already
> runs that file over https, and everything that needs a responder is
> in the new t5585.
>
> A note on the testing stuff. SSLUseStapling makes apache
> create a mutex in a compiled-in system-wide runtime directory.
> I set DefaultRuntimeDir in the OCSP block to keep that
> mutex in the server root, the other way resolved to a path
> on my box that didn't exist and prevented the server from starting.
>
> Changes since v6:
> - added t5585 and LIB_HTTPD_OCSP support in lib-httpd, taken
> from Patrick's patch
> - moved the SSL_VERIFYSTATUS prereq into lib-httpd.sh so both
> files share one definition
The updated tests look good; will replace. Thanks.