mirror of
https://github.com/git/git.git
synced 2026-10-04 21:57:29 +02:00
git never sets CURLOPT_SSL_VERIFYSTATUS, so libcurl never requests the
OCSP "Certificate Status Request" extension and any stapled response a
server sends is ignored, including responses that explicitly state the
certificate has been revoked.
Add an http.sslVerifyStatus boolean that maps to
CURLOPT_SSL_VERIFYSTATUS. http_options() is already the collect_fn for a
urlmatch config, so the per-URL form works with no changes:
git config http.https://example.com/.sslVerifyStatus true
Defaults to false/"off". This is due to the nature of the OCSP protocol.
If enabled, git would expect to receive OCSP stapled responses. If the
stapled responses were not present, the connection would be blocked as
the status of the server's certificate could not be verified. This would
break connections to legitimate services that don't use OCSP as their
certificate revocation mechanism.
If the backend can't check the staple, curl_easy_setopt() returns
CURLE_NOT_BUILT_IN. The error message includes curl_easy_strerror()
along with the option name, so a libcurl built without status
verification is easy to identify.
CURLOPT_SSL_VERIFYSTATUS has existed since libcurl 7.41.0, below our
7.61.0 floor, so no version guard is needed.
The tests that need no OCSP infrastructure stay in t5551, which t5559
runs over https. The rest need a certificate authority, a responder to
answer for it and a server configured to staple, so lib-httpd gains an
opt-in LIB_HTTPD_OCSP mode and t5585 uses it to check that a "good"
staple is accepted, a "revoked" one is refused, and that the revoked one
is ignored when the option is off.
Signed-off-by: Grayson Gordon <graysongordon1@gmail.com>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
36 lines
771 B
INI
36 lines
771 B
INI
[ ca ]
|
|
default_ca = CA_default
|
|
|
|
[ CA_default ]
|
|
dir = $ENV::OCSP_CA_DIR
|
|
database = $dir/index.txt
|
|
new_certs_dir = $dir/newcerts
|
|
serial = $dir/serial
|
|
default_md = sha256
|
|
default_days = 2
|
|
policy = policy_anything
|
|
email_in_dn = no
|
|
unique_subject = no
|
|
x509_extensions = server_cert
|
|
|
|
[ policy_anything ]
|
|
commonName = supplied
|
|
|
|
[ req ]
|
|
default_bits = 2048
|
|
distinguished_name = req_distinguished_name
|
|
prompt = no
|
|
|
|
[ req_distinguished_name ]
|
|
# The subject is always given on the command line via -subj.
|
|
|
|
[ v3_ca ]
|
|
basicConstraints = critical, CA:TRUE
|
|
keyUsage = critical, digitalSignature, keyCertSign, cRLSign
|
|
subjectKeyIdentifier = hash
|
|
|
|
[ server_cert ]
|
|
basicConstraints = CA:FALSE
|
|
subjectAltName = IP:127.0.0.1
|
|
authorityInfoAccess = OCSP;URI:$ENV::OCSP_URI
|