Edit report at https://bugs.php.net/bug.php?id=68575&edit=1
ID: 68575
Updated by: cmb@php.net
Reported by: scott at arciszewski dot me
Summary: Upgrade cURL to at least 7.39.0 for pinnedpubkey
support
-Status: Open
+Status: Closed
Type: Feature/Change Request
Package: cURL related
Operating System: All
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> Asked in room 11, and Nikita says this should be as simple as> defining the constant.
Indeed, and that has happened as of PHP 7.0.7.
Previous Comments:
------------------------------------------------------------------------
[2016-04-21 15:36:12] scott at arciszewski dot me
Asked in room 11, and Nikita says this should be as simple as defining the constant.
------------------------------------------------------------------------
[2015-11-25 16:40:12] ebc82ab1 at opayq dot com
This issue is a quite old one and in the future secure encrypted communication becomes more
imported. And as public key pinning is a really nice feature which can restrict the risk of rogue
CAs very much it would be very nice if this feature could also be added to PHP.
As you can see it was implemented in cURL some months before this issue here was opened:
http://curl.haxx.se/mail/lib-2014-08/0224.html
[In the doc](http://curl.haxx.se/docs/manpage.html) it also shows the exact version numbers of cURL
to be used with different ssl/tls libaries:
> Added in 7.39.0 for OpenSSL, GnuTLS and GSKit. Added in 7.43.0 for NSS and wolfSSL/CyaSSL.
> sha256 support added in 7.44.0 for OpenSSL, GnuTLS, NSS and wolfSSL/CyaSSL. Other SSL backends not
> supported.
BTW here a Stackoverflow question about this: https://stackoverflow.com/questions/27112356/tls-public-key-pinning-with-php-curl
Regards,
rugk
------------------------------------------------------------------------
[2014-12-09 15:08:32] scott at arciszewski dot me
Description:
------------
Curl 7.39.00 supports a --pinnedpubkey flag which allows you to pin the public key used by the
connection, and abort otherwise.
http://curl.haxx.se/docs/manpage.html
Test script:
---------------
<?php
// Desired usage:
$ch = curl_init("https://example.com");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_PINNED_PUBKEY, $pem_public_key);
$result = curl_exec($ch);
if ($result !== false) {
var_dump($result);
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68575&edit=1