Edit report at https://bugs.php.net/bug.php?id=68575&edit=1
ID: 68575
Updated by: cmb@php.net
Reported by: scott at arciszewski dot me
Summary: Upgrade cURL to at least 7.39.0 for pinnedpubkey
support
Status: Re-Opened
Type: Feature/Change Request
Package: cURL related
Operating System: All
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Improved the docs[1] and submitted a PR wrt. the error constant[2].
[1] <http://svn.php.net/viewvc?view=revision&revision=340038>
[2] <https://github.com/php/php-src/pull/2128>
Previous Comments:
------------------------------------------------------------------------
[2016-09-15 09:13:41] cmb@php.net
The option is actually called CULROPT_PINNEDPUBLICKEY, and it's
already basically documented. The docs need to be improved; see
<https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html>.
Also the error constant CURLE_SSL_PINNEDPUBKEYNOTMATCH has to be
implemented.
------------------------------------------------------------------------
[2016-09-14 21:38:02] rugk at posteo dot de
So how can this be used in PHP?
When will the doc (I assume https://secure.php.net/manual/de/function.curl-setopt.php)
be updated?
------------------------------------------------------------------------
[2016-07-03 16:56:54] cmb@php.net
> Asked in room 11, and Nikita says this should be as simple as> defining the constant.
Indeed, and that has happened as of PHP 7.0.7.
------------------------------------------------------------------------
[2016-04-21 15:36:12] scott at arciszewski dot me
Asked in room 11, and Nikita says this should be as simple as defining the constant.
------------------------------------------------------------------------
[2015-11-25 16:40:12] ebc82ab1 at opayq dot com
This issue is a quite old one and in the future secure encrypted communication becomes more
imported. And as public key pinning is a really nice feature which can restrict the risk of rogue
CAs very much it would be very nice if this feature could also be added to PHP.
As you can see it was implemented in cURL some months before this issue here was opened:
http://curl.haxx.se/mail/lib-2014-08/0224.html
[In the doc](http://curl.haxx.se/docs/manpage.html) it also shows the exact version numbers of cURL
to be used with different ssl/tls libaries:
> Added in 7.39.0 for OpenSSL, GnuTLS and GSKit. Added in 7.43.0 for NSS and wolfSSL/CyaSSL.
> sha256 support added in 7.44.0 for OpenSSL, GnuTLS, NSS and wolfSSL/CyaSSL. Other SSL backends not
> supported.
BTW here a Stackoverflow question about this: https://stackoverflow.com/questions/27112356/tls-public-key-pinning-with-php-curl
Regards,
rugk
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68575
--
Edit this bug report at https://bugs.php.net/bug.php?id=68575&edit=1