Bug 13585

Summary: git clone using https fails on CentOS 8 with 'unsupported protocol'
Product: [Infrastructure] Website Reporter: Connor Imes <cimes>
Component: web-contentAssignee: Michael Halstead <mhalstead>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: jefro, ndec13, randy.macleod
Version: unspecified   
Target Milestone: Q4   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Don't know

Description Connor Imes 2019-10-08 14:07:11 UTC
Running CentOS 8, using a mostly minimal installation, I tried to clone the poky repository but received the following error:

$ git clone https://git.yoctoproject.org/git/poky
Cloning into 'poky'...
fatal: unable to access 'https://git.yoctoproject.org/git/poky/': error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol

$ cat /etc/redhat-release 
CentOS Linux release 8.0.1905 (Core) 
$ openssl version
OpenSSL 1.1.1 FIPS  11 Sep 2018
$ git --version
git version 2.18.1

Trying different 'tlsv1.*' values for the environment variable 'GIT_SSL_VERSION' did not help ('tlsv1.3' resulted in a different error: 'error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure').

I have not had trouble cloning other repositories using https (e.g., from Github). Cloning poky from 'git://git.yoctoproject.org/poky' works as expected.
Comment 1 Randy MacLeod 2019-10-10 14:49:40 UTC
Konrad can you or Peiran look at this for 3.1-M1.
Comment 2 Konrad Scherer 2019-10-10 16:24:53 UTC
The certificate for https://git.yoctoproject.org uses TLS v1.0 and this is not supported by the openssl version in CentOS 8. 

On Ubuntu 19.04:

> openssl s_client -connect git.yoctoproject.org:443
New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1
    Cipher    : ECDHE-RSA-AES256-SHA

On CentOS 8:

> openssl s_client -connect git.yoctoproject.org:443
CONNECTED(00000004)
139948769191744:error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol:ssl/statem/statem_lib.c:1907:

specifying the TLS version for openssl works
> openssl s_client -connect git.yoctoproject.org:443 -tls1
New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA
Server public key is 2048 bit

but specifying the TLS version for curl doesn't work
> curl --tlsv1 https://git.yoctoproject.org/
curl: (35) error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol

This may be a bug in curl, but since git uses libcurl disabling git ssl verification doesn't work and setting the sslVersion to tlsv1.0 doesn't work either.

This probably needs to fixed at the http server config which seems to only support TLS 1.0
Comment 3 Michael Halstead 2020-02-14 12:29:14 UTC
I've tested the TLS upgrades on CentOS8 and they are working now.