From: Junio C Hamano Date: Wed, 16 Sep 2026 19:29:04 GMT Subject: Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses Message-ID: In-Reply-To: <20260915162348.97792-1-ggordon@gitlab.com> graysongordon-gl writes: > From: Grayson Gordon > > git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the > OCSP "Certificate Status Request" extension and any stapled response a > server sends is ignored, including responses that explicitly state the > certificate has been revoked. > > Add an http.sslVerifyStatus boolean that maps to > CURLOPT_SSL_VERIFYSTATUS. http_options() is already the collect_fn for a > urlmatch config, so the per-URL form works with no changes: > --- > > Junio, Patrick: this is the combined version we discussed. The > cases that need no OCSP setup stayed in t5551, since t5559 already > runs that file over https, and everything that needs a responder is > in the new t5585. > > A note on the testing stuff. SSLUseStapling makes apache > create a mutex in a compiled-in system-wide runtime directory. > I set DefaultRuntimeDir in the OCSP block to keep that > mutex in the server root, the other way resolved to a path > on my box that didn't exist and prevented the server from starting. > > Changes since v6: > - added t5585 and LIB_HTTPD_OCSP support in lib-httpd, taken > from Patrick's patch > - moved the SSL_VERIFYSTATUS prereq into lib-httpd.sh so both > files share one definition The updated tests look good; will replace. Thanks.