| Summary: | git clone using https fails on CentOS 8 with 'unsupported protocol' | ||
|---|---|---|---|
| Product: | [Infrastructure] Website | Reporter: | Connor Imes <cimes> |
| Component: | web-content | Assignee: | Michael Halstead <mhalstead> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | normal | ||
| Priority: | Medium+ | CC: | jefro, ndec13, randy.macleod |
| Version: | unspecified | ||
| Target Milestone: | Q4 | ||
| Hardware: | x86 | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | Don't know | |
|
Description
Connor Imes
2019-10-08 14:07:11 UTC
Konrad can you or Peiran look at this for 3.1-M1. The certificate for https://git.yoctoproject.org uses TLS v1.0 and this is not supported by the openssl version in CentOS 8. On Ubuntu 19.04: > openssl s_client -connect git.yoctoproject.org:443 New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1 Cipher : ECDHE-RSA-AES256-SHA On CentOS 8: > openssl s_client -connect git.yoctoproject.org:443 CONNECTED(00000004) 139948769191744:error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol:ssl/statem/statem_lib.c:1907: specifying the TLS version for openssl works > openssl s_client -connect git.yoctoproject.org:443 -tls1 New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA Server public key is 2048 bit but specifying the TLS version for curl doesn't work > curl --tlsv1 https://git.yoctoproject.org/ curl: (35) error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol This may be a bug in curl, but since git uses libcurl disabling git ssl verification doesn't work and setting the sslVersion to tlsv1.0 doesn't work either. This probably needs to fixed at the http server config which seems to only support TLS 1.0 I've tested the TLS upgrades on CentOS8 and they are working now. |