Req #68575 [Csd->ReO]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support

From: Date: Thu, 15 Sep 2016 09:13:43 +0000
Subject: Req #68575 [Csd->ReO]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204055@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68575&edit=1

 ID:                 68575
 Updated by:         cmb@php.net
 Reported by:        scott at arciszewski dot me
 Summary:            Upgrade cURL to at least 7.39.0 for pinnedpubkey
                     support
-Status:             Closed
+Status:             Re-Opened
 Type:               Feature/Change Request
 Package:            cURL related
 Operating System:   All
 PHP Version:        Irrelevant
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The option is actually called CULROPT_PINNEDPUBLICKEY, and it's
already basically documented. The docs need to be improved; see
<https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html>.
Also the error constant CURLE_SSL_PINNEDPUBKEYNOTMATCH has to be
implemented.


Previous Comments:
------------------------------------------------------------------------
[2016-09-14 21:38:02] rugk at posteo dot de

So how can this be used in PHP?
When will the doc (I assume https://secure.php.net/manual/de/function.curl-setopt.php)
be updated?

------------------------------------------------------------------------
[2016-07-03 16:56:54] cmb@php.net

> Asked in room 11, and Nikita says this should be as simple as
> defining the constant.

Indeed, and that has happened as of PHP 7.0.7.

------------------------------------------------------------------------
[2016-04-21 15:36:12] scott at arciszewski dot me

Asked in room 11, and Nikita says this should be as simple as defining the constant.

------------------------------------------------------------------------
[2015-11-25 16:40:12] ebc82ab1 at opayq dot com

This issue is a quite old one and in the future secure encrypted communication becomes more
imported. And as public key pinning is a really nice feature which can restrict the risk of rogue
CAs very much it would be very nice if this feature could also be added to PHP.

As you can see it was implemented in cURL some months before this issue here was opened:
http://curl.haxx.se/mail/lib-2014-08/0224.html

[In the doc](http://curl.haxx.se/docs/manpage.html) it also shows the exact version numbers of cURL
to be used with different ssl/tls libaries:
> Added in 7.39.0 for OpenSSL, GnuTLS and GSKit. Added in 7.43.0 for NSS and wolfSSL/CyaSSL.
> sha256 support added in 7.44.0 for OpenSSL, GnuTLS, NSS and wolfSSL/CyaSSL. Other SSL backends not
> supported. 

BTW here a Stackoverflow question about this: https://stackoverflow.com/questions/27112356/tls-public-key-pinning-with-php-curl

Regards,
rugk

------------------------------------------------------------------------
[2014-12-09 15:08:32] scott at arciszewski dot me

Description:
------------
Curl 7.39.00 supports a --pinnedpubkey flag which allows you to pin the public key used by the
connection, and abort otherwise.

http://curl.haxx.se/docs/manpage.html

Test script:
---------------
<?php
// Desired usage:

$ch = curl_init("https://example.com");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_PINNED_PUBKEY, $pem_public_key);
$result = curl_exec($ch);

if ($result !== false) {
  var_dump($result);
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68575&edit=1


Thread (12 messages)

« previous php.bugs (#204055) next »