threads / patch / 48182

v4Allow use of TLS 1.3

Subject: [PATCH v4] Allow use of TLS 1.3

## tl;dr

3 messages between Mar 29, 2018 and Mar 29, 2018. Diffs are folded; open one to read it.

replies: 2people: 3as markdown or json

Loganaden Velvindron· Mar 29, 2018, 10:14 UTC · lore

Add a tlsv1.3 option to http.sslVersion in addition to the existing tlsv1.[012] options. libcurl has supported this since 7.52.0.

This requires OpenSSL 1.1.1 with TLS 1.3 enabled or curl built with recent versions of NSS or BoringSSL as the TLS backend.

Signed-off-by: Loganaden Velvindron <logan@hackers.mu>
---
 Documentation/config.txt | 1 +
 http.c                   | 3 +++
 2 files changed, 4 insertions(+)
Show changes to 2 files +4 −0

Documentation/config.txt, http.c

diff --git a/Documentation/config.txt b/Documentation/config.txt
index ce9102cea..f31d62772 100644
--- a/Documentation/config.txt
+++ b/Documentation/config.txt
@@ -1957,6 +1957,7 @@ http.sslVersion::
 	- tlsv1.0
 	- tlsv1.1
 	- tlsv1.2
+	- tlsv1.3
 
 +
 Can be overridden by the `GIT_SSL_VERSION` environment variable.
diff --git a/http.c b/http.c
index a5bd5d62c..f84b18551 100644
--- a/http.c
+++ b/http.c
@@ -62,6 +62,9 @@ static struct {
 	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
 	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
 #endif
+#if LIBCURL_VERSION_NUM >= 0x073400
+	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
+#endif
 };
 #if LIBCURL_VERSION_NUM >= 0x070903
 static const char *ssl_key;
-- 
2.16.2
Johannes Schindelin· Mar 29, 2018, 15:03 UTC · re: Loganaden Velvindron · lore

Re: [PATCH v4] Allow use of TLS 1.3

Hi Logan,
On Thu, 29 Mar 2018, Loganaden Velvindron wrote:
Show 5 quoted lines
> Add a tlsv1.3 option to http.sslVersion in addition to the existing
> tlsv1.[012] options. libcurl has supported this since 7.52.0.
> 
> This requires OpenSSL 1.1.1 with TLS 1.3 enabled or curl built with
> recent versions of NSS or BoringSSL as the TLS backend.

Thank you, Johannes

Junio C Hamano· Mar 29, 2018, 20:40 UTC · re: Loganaden Velvindron · lore

Re: [PATCH v4] Allow use of TLS 1.3

Loganaden Velvindron <logan@hackers.mu> writes:
Show 10 quoted lines
> diff --git a/http.c b/http.c
> index a5bd5d62c..f84b18551 100644
> --- a/http.c
> +++ b/http.c
> @@ -62,6 +62,9 @@ static struct {
>  	{ "tlsv1.1", CURL_SSLVERSION_TLSv1_1 },
>  	{ "tlsv1.2", CURL_SSLVERSION_TLSv1_2 },
>  #endif
> +#if LIBCURL_VERSION_NUM >= 0x073400
> +	{ "tlsv1.3", CURL_SSLVERSION_TLSv1_3 }
Looks OK to me, except one minor nit.

I'll add a trailing comma for this entry while queuing, so that a future patch to add tlsv1.4 or whatever won't have to worry about it.

Thanks.
> +#endif
>  };
>  #if LIBCURL_VERSION_NUM >= 0x070903
>  static const char *ssl_key;

← back to recent threads