]> git.ipfire.org Git - thirdparty/git.git/commit
t/lib-httpd: increase ssl key size to 2048 bits
authorJeff King <peff@peff.net>
Wed, 1 Feb 2023 11:39:26 +0000 (06:39 -0500)
committerJunio C Hamano <gitster@pobox.com>
Wed, 1 Feb 2023 18:10:34 +0000 (10:10 -0800)
commitb08edf709dfcd79c3691370930cd89c4b9b16d2f
tree3029da43bb055b228c9500905d9e002ffb4a434c
parentd113449e265d1914e55f67f0e14e26a8d784b987
t/lib-httpd: increase ssl key size to 2048 bits

Recent versions of openssl will refuse to work with 1024-bit RSA keys,
as they are considered insecure. I didn't track down the exact version
in which the defaults were tightened, but the Debian-package openssl 3.0
on my system yields:

  $ LIB_HTTPD_SSL=1 ./t5551-http-fetch-smart.sh -v -i
  [...]
  SSL Library Error: error:0A00018F:SSL routines::ee key too small
  1..0 # SKIP web server setup failed

This could probably be overcome with configuration, but that's likely
to be a headache (especially if it requires touching /etc/openssl).
Let's just pick a key size that's less outrageously out of date.

Signed-off-by: Jeff King <peff@peff.net>
Signed-off-by: Junio C Hamano <gitster@pobox.com>
t/lib-httpd/ssl.cnf