Running CentOS 8, using a mostly minimal installation, I tried to clone the poky repository but received the following error: $ git clone https://git.yoctoproject.org/git/poky Cloning into 'poky'... fatal: unable to access 'https://git.yoctoproject.org/git/poky/': error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol $ cat /etc/redhat-release CentOS Linux release 8.0.1905 (Core) $ openssl version OpenSSL 1.1.1 FIPS 11 Sep 2018 $ git --version git version 2.18.1 Trying different 'tlsv1.*' values for the environment variable 'GIT_SSL_VERSION' did not help ('tlsv1.3' resulted in a different error: 'error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure'). I have not had trouble cloning other repositories using https (e.g., from Github). Cloning poky from 'git://git.yoctoproject.org/poky' works as expected.
Konrad can you or Peiran look at this for 3.1-M1.
The certificate for https://git.yoctoproject.org uses TLS v1.0 and this is not supported by the openssl version in CentOS 8. On Ubuntu 19.04: > openssl s_client -connect git.yoctoproject.org:443 New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA Server public key is 2048 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1 Cipher : ECDHE-RSA-AES256-SHA On CentOS 8: > openssl s_client -connect git.yoctoproject.org:443 CONNECTED(00000004) 139948769191744:error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol:ssl/statem/statem_lib.c:1907: specifying the TLS version for openssl works > openssl s_client -connect git.yoctoproject.org:443 -tls1 New, TLSv1.0, Cipher is ECDHE-RSA-AES256-SHA Server public key is 2048 bit but specifying the TLS version for curl doesn't work > curl --tlsv1 https://git.yoctoproject.org/ curl: (35) error:1425F102:SSL routines:ssl_choose_client_version:unsupported protocol This may be a bug in curl, but since git uses libcurl disabling git ssl verification doesn't work and setting the sslVersion to tlsv1.0 doesn't work either. This probably needs to fixed at the http server config which seems to only support TLS 1.0
I've tested the TLS upgrades on CentOS8 and they are working now.