# [PATCH] Allow use of TLS 1.3

4 messages from 2018-03-23 to 2018-03-23. Participants: Loganaden Velvindron, Ævar Arnfjörð Bjarmason, Johannes Schindelin.
Thread: https://gitlist.dev/t/48128

## Loganaden Velvindron, 2018-03-23 18:25

Subject: [PATCH] Allow use of TLS 1.3
Message-ID: <20180323182506.GA15493@voidlinux>
URL: https://gitlist.dev/e/20180323182506.GA15493%40voidlinux

```
Done during IETF 101 hackathon

Signed-off-by: Loganaden Velvindron <logan@hackers.mu>
---
 Documentation/config.txt | 1 +
 http.c                   | 3 +++
 2 files changed, 4 insertions(+)

diff --git a/Documentation/config.txt b/Documentation/config.txt
index ce9102cea..f31d62772 100644
--- a/Documentation/config.txt
+++ b/Documentation/config.txt
@@ -1957,6 +1957,7 @@ http.sslVersion::
 	- tlsv1.0
 	- tlsv1.1
 	- tlsv1.2
+	- tlsv1.3
 
 +
 Can be overridden by the `GIT_SSL_VERSION` environment variable.
diff --git a/http.c b/http.c
index 8c11156ae..666fe31f3 100644
--- a/http.c
+++ b/http.c
@@ -61,6 +61,9 @@ static struct {
 	{ "tlsv1.0", CURL_SSLVERSION_TLSv1_0 },
 	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
 	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
+#if LIBCURL_VERSION_NUM >= 0x075200
+	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
+#endif
 #endif
 };
 #if LIBCURL_VERSION_NUM >= 0x070903
-- 
2.16.2


```

## Ævar Arnfjörð Bjarmason, 2018-03-23 18:37

Subject: Re: [PATCH] Allow use of TLS 1.3
Message-ID: <87in9my6y3.fsf@evledraar.gmail.com>
URL: https://gitlist.dev/e/87in9my6y3.fsf%40evledraar.gmail.com
In-Reply-To: <20180323182506.GA15493@voidlinux>

```

On Fri, Mar 23 2018, Loganaden Velvindron wrote:

> Done during IETF 101 hackathon

Hi. Thanks. Let's add a meaningful commit message to this though,
something like:

    Add a tlsv1.3 option to http.sslVersion in addition to the existing
    tlsv1.[012] options. libcurl has supported this since 7.52.0.

> --- a/http.c
> +++ b/http.c
> @@ -61,6 +61,9 @@ static struct {
>  	{ "tlsv1.0", CURL_SSLVERSION_TLSv1_0 },
>  	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
>  	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
> +#if LIBCURL_VERSION_NUM >= 0x075200
> +	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
> +#endif

I wonder if this wouldn't be better as:

    +#ifdef CURL_SSLVERSION_TLSv1_3
    +	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
    +#endif

We've been bitten before by doing version checks on libcurl code, only
to find that some distros are actively backporting features, so checking
the specific macros is usually better.

>  #endif
>  };
>  #if LIBCURL_VERSION_NUM >= 0x070903

```

## Loganaden Velvindron, 2018-03-23 18:39

Subject: Re: [PATCH] Allow use of TLS 1.3
Message-ID: <20180323183950.GA15994@voidlinux>
URL: https://gitlist.dev/e/20180323183950.GA15994%40voidlinux
In-Reply-To: <87in9my6y3.fsf@evledraar.gmail.com>

```
On Fri, Mar 23, 2018 at 07:37:08PM +0100, Ævar Arnfjörð Bjarmason wrote:
> 
> On Fri, Mar 23 2018, Loganaden Velvindron wrote:
> 
> > Done during IETF 101 hackathon
> 
> Hi. Thanks. Let's add a meaningful commit message to this though,
> something like:
> 
>     Add a tlsv1.3 option to http.sslVersion in addition to the existing
>     tlsv1.[012] options. libcurl has supported this since 7.52.0.

Looks good to me.

> 
> > --- a/http.c
> > +++ b/http.c
> > @@ -61,6 +61,9 @@ static struct {
> >  	{ "tlsv1.0", CURL_SSLVERSION_TLSv1_0 },
> >  	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
> >  	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
> > +#if LIBCURL_VERSION_NUM >= 0x075200
> > +	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
> > +#endif
> 
> I wonder if this wouldn't be better as:
> 
>     +#ifdef CURL_SSLVERSION_TLSv1_3
>     +	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
>     +#endif
> 
> We've been bitten before by doing version checks on libcurl code, only
> to find that some distros are actively backporting features, so checking
> the specific macros is usually better.

This looks good to me as well. I will send Patch v2, with the suggestions.

> 
> >  #endif
> >  };
> >  #if LIBCURL_VERSION_NUM >= 0x070903

```

## Johannes Schindelin, 2018-03-23 23:37

Subject: Re: [PATCH] Allow use of TLS 1.3
Message-ID: <nycvar.QRO.7.76.6.1803240035300.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz>
URL: https://gitlist.dev/e/nycvar.QRO.7.76.6.1803240035300.77%40ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz
In-Reply-To: <20180323183950.GA15994@voidlinux>

```
Hi,

On Fri, 23 Mar 2018, Loganaden Velvindron wrote:

> On Fri, Mar 23, 2018 at 07:37:08PM +0100, Ævar Arnfjörð Bjarmason wrote:
> > 
> > On Fri, Mar 23 2018, Loganaden Velvindron wrote:
> > 
> > > Done during IETF 101 hackathon
> > 
> > Hi. Thanks. Let's add a meaningful commit message to this though,
> > something like:
> > 
> >     Add a tlsv1.3 option to http.sslVersion in addition to the existing
> >     tlsv1.[012] options. libcurl has supported this since 7.52.0.

Can we please also add that OpenSSL 1.1.* is required (or that cURL is
built with NSS or BoringSSL as the TLS backend)?

Thanks,
Johannes
```
