threads / patch / 48149

v3Allow use of TLS 1.3

Subject: [PATCH v3] Allow use of TLS 1.3

## tl;dr

3 messages between Mar 26, 2018 and Mar 26, 2018. Diffs are folded; open one to read it.

replies: 2people: 3as markdown or json

Loganaden Velvindron· Mar 26, 2018, 09:24 UTC · lore

Add a tlsv1.3 option to http.sslVersion in addition to the existing tlsv1.[012] options. libcurl has supported this since 7.52.0.

Signed-off-by: Loganaden Velvindron <logan@hackers.mu>
---
 Documentation/config.txt | 1 +
 http.c                   | 3 +++
 2 files changed, 4 insertions(+)
Show changes to 2 files +4 −0

Documentation/config.txt, http.c

diff --git a/Documentation/config.txt b/Documentation/config.txt
index ce9102cea..f31d62772 100644
--- a/Documentation/config.txt
+++ b/Documentation/config.txt
@@ -1957,6 +1957,7 @@ http.sslVersion::
 	- tlsv1.0
 	- tlsv1.1
 	- tlsv1.2
+	- tlsv1.3
 
 +
 Can be overridden by the `GIT_SSL_VERSION` environment variable.
diff --git a/http.c b/http.c
index a5bd5d62c..f84b18551 100644
--- a/http.c
+++ b/http.c
@@ -62,6 +62,9 @@ static struct {
 	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
 	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
 #endif
+#if LIBCURL_VERSION_NUM >= 0x073400
+	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
+#endif
 };
 #if LIBCURL_VERSION_NUM >= 0x070903
 static const char *ssl_key;
-- 
2.16.2
Johannes Schindelin· Mar 26, 2018, 21:38 UTC · re: Loganaden Velvindron · lore

Re: [PATCH v3] Allow use of TLS 1.3

Hi Logan,
On Mon, 26 Mar 2018, Loganaden Velvindron wrote:
> Add a tlsv1.3 option to http.sslVersion in addition to the existing
> tlsv1.[012] options. libcurl has supported this since 7.52.0.
> 
> Signed-off-by: Loganaden Velvindron <logan@hackers.mu>

Can we *please* also add that OpenSSL 1.1.* is required (or that cURL is built with NSS or BoringSSL as the TLS backend)?

See https://public-inbox.org/git/nycvar.QRO.7.76.6.1803240035300.77@ZVAVAG-6OXH6DA.rhebcr.pbec.zvpebfbsg.pbz/ for my original please.

I deem this information *really* important because a lot of Git packages are still built against OpenSSL 1.0.2 (e.g. Git for Windows) and *won't* benefit immediately from your patch.

Ciao, Johannes

Daniel Stenberg· Mar 26, 2018, 21:46 UTC · re: Johannes Schindelin · lore

Re: [PATCH v3] Allow use of TLS 1.3

On Mon, 26 Mar 2018, Johannes Schindelin wrote:
> Can we *please* also add that OpenSSL 1.1.* is required (or that cURL is 
> built with NSS or BoringSSL as the TLS backend)?

We might consider adding a way to extract that info from curl to make that work really good for you. There are now six TLS libraries that support TLS 1.3 and it might be hard for git to figure out the exact situation for each library and keep track of these moving targets...

-- 
  / daniel.haxx.se

← back to recent threads