git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] add support for specifying an SSL cipher list

From
Junio C Hamano <gitster@pobox.com>
Date
May 7, 2015, 16:33 UTC
Message-ID
<xmqqvbg4qreq.fsf@gitster.dls.corp.google.com>
In-Reply-To
<20150507160413.GB16334@redhat.com>
Lars Kellogg-Stedman <lars@redhat.com> writes:
Show 9 quoted lines
> [Apologies for the dupe; this should have been cc'd to the list]
>
>> It is not clear to me what definition of "override" this sentence
>> uses.
>
> I was using it in what I thought was the common sense of "git will use
> the value in the environment variable if it exists rather than any
> value in the git configuration".  I apologize if this wasn't clear;
> can you suggest how I might rephrase that?

I was hinting that the usual "override" that needs to specify the list to be used exactly would not be very useful, in that people often want to say one of the three things:

 - allow this to be used in addition to what you usually use; or
 - what you usually use is fine, but never use this one as it was
   recently discovered to be insecure; or
 - I have something nonstandard configured but ignore that
   configuration for this invocation only and reset to the default
   behaviour.

If you are changing the behaviour in your reroll, I suspect you wouldn't be doing the common "override". If you are going to do the 'reset on empty', then 'You can set the environment variable to an empty string to reset to the default cipher list used by libcURL.' may be a natural way to describe it.

I briefly wondered if lack of the other two ("allow this too", "forbid this") might become an issue not just for the environment, but also for the configuration variable. It is probably not a huge issue because you can say "http.<url>.sslCipherList" to limit the scope of the affected site [*1*].

CURLOPT_SSL_CIPHER_LIST appeared in cURL 7.9 which is relatively ancient, so it should be safe to use (please write that down in your commit log message).

Thanks.
[Footnote]
*1* And it is a bad idea to address "allow this too" and "forbid
    this" at our level---the semantics of CURLOPT_SSL_CIPHER_LIST
    given by libcURL itself depends on the crypto backend (when
    using OpenSSL and GnuTLS, you can say !, +, - to tweak; when
    using NSS, you can only say "use these and nothing else").
Previous: Lars Kellogg-StedmanNext: Lars Kellogg-Stedman
Message 4 of 20 in “add support for specifying an SSL cipher list”
  1. add support for specifying an SSL cipher listLars Kellogg-Stedman, May 7, 2015
  2. Junio C HamanoMay 7, 2015
  3. Lars Kellogg-StedmanMay 7, 2015
  4. Junio C HamanoMay 7, 2015
  5. Lars Kellogg-StedmanMay 7, 2015
  6. http: add support for specifying an SSL cipher listLars Kellogg-Stedman, May 7, 2015
  7. Tay Ray ChuanMay 7, 2015
  8. Lars Kellogg-StedmanMay 7, 2015
  9. http: add support for specifying an SSL cipher listLars Kellogg-Stedman, May 7, 2015
  10. Eric SunshineMay 7, 2015
  11. Lars Kellogg-StedmanMay 7, 2015
  12. Eric SunshineMay 7, 2015
  13. Junio C HamanoMay 7, 2015
  14. http: add support for specifying an SSL cipher listLars Kellogg-Stedman, May 8, 2015
  15. Eric SunshineMay 8, 2015
  16. SZEDER GáborMay 8, 2015
  17. Junio C HamanoMay 8, 2015
  18. http: add support for specifying an SSL cipher listLars Kellogg-Stedman, May 8, 2015
  19. Lars Kellogg-StedmanMay 14, 2015
  20. Eric SunshineMay 14, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.