Re: [PATCH v7] http: add http.sslVerifyStatus to check stapled OCSP responses
- From
Junio C Hamano <gitster@pobox.com>
- Date
- Sep 23, 2026, 21:47 UTC
- Message-ID
- <xmqqwlsb63o9.fsf@gitster.g>
- In-Reply-To
- <arQ/nOH+o3XwQFD/@szeder.dev>
SZEDER Gábor <szeder.dev@gmail.com> writes:
Show 10 quoted lines
> On Tue, Sep 15, 2026 at 12:23:48PM -0400, graysongordon-gl wrote: >> From: Grayson Gordon <graysongordon1@gmail.com> >> >> git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the >> OCSP "Certificate Status Request" extension and any stapled response a >> server sends is ignored, including responses that explicitly state the >> certificate has been revoked. > ... > This patch was merged to 'next' the other day, and the last test in > the new t5585 fails on my system.
Sorry about a premature merge. Since we are not in a hurry to take this topic in (or no new feature topic in general), let me revert it out of 'next' and give it a clean slate to try again.
Show 10 quoted lines
> ... > I added that 'cat err' to see the error message. Turns out that 'git > ls-remote' can't even find the repository on the remote, but the > prereq is still considered fulfilled. Is that right? > ... > This time the error message talks about missing OCSP response, but the > prereq is still considered fulfilled. Again: is that right?! > > Instead of the lack of a certain string in the error message, is > there something positive that we can test instead?
Oh, that is a very constructive and useful suggestion. Greatly appreciated.
Show 21 quoted lines
> So this test case fails for me with the following trace output: > > expecting success of 5585.5 'revoked certificate is accepted without http.sslVerifyStatus': > with_ssl_verification git ls-remote "$HTTPD_URL/smart/repo.git" >actual && > test_line_count -gt 0 actual > > + with_ssl_verification git ls-remote https://127.0.0.1:5585/smart/repo.git > + sane_unset GIT_SSL_NO_VERIFY > + unset GIT_SSL_NO_VERIFY > + return 0 > + GIT_SSL_CAINFO=/home/szeder/src/git/t/trash directory.t5585-http-ssl-ocsp/httpd/ca.pem git ls-remote https://127.0.0.1:5585/smart/repo.git > fatal: unable to access 'https://127.0.0.1:5585/smart/repo.git/': server certificate verification failed. CAfile: /home/szeder/src/git/t/trash directory.t5585-http-ssl-ocsp/httpd/ca.pem CRLfile: none > error: last command exited with $?=128 > not ok 5 - revoked certificate is accepted without http.sslVerifyStatus > # > # with_ssl_verification git ls-remote "$HTTPD_URL/smart/repo.git" >actual && > # test_line_count -gt 0 actual > # > > libcurl is 7.81.0, apache is 2.4.52 (whatever is shipped in this > slowly aging LTS...)
Thanks.