Req #68575 [Com]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support
| From: | rugk at posteo dot de | Date: | Sun, 18 Sep 2016 12:06:54 +0000 |
| Subject: | Req #68575 [Com]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204110@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68575&edit=1
ID: 68575
Comment by: rugk at posteo dot de
Reported by: scott at arciszewski dot me
Summary: Upgrade cURL to at least 7.39.0 for pinnedpubkey
support
Status: Re-Opened
Type: Feature/Change Request
Package: cURL related
Operating System: All
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Oh I meant "in PHP < 7.0.7" of course.
Previous Comments:
------------------------------------------------------------------------
[2016-09-18 12:06:03] rugk at posteo dot de
So if it is just the constant definition, which was missing, am I right that I could manually define
the constant CURLOPT_PINNEDPUBLICKEY in PHP > 7.0.7 to use it?
<?php
defined('CURLOPT_PINNEDPUBLICKEY') || define('CURLOPT_PINNEDPUBLICKEY', 1234);
$ch = curl_init("https://example.com");
curl_setopt($ch, CURLOPT_PINNEDPUBLICKEY,
"sha256//YhKJKSzoTt2b5FP18fvpHo7fJYqQCjAa3HWY3tvRMwE=;sha256//t62CeU2tQiqkexU74Gxa2eg7fRbEgoChTociMee9wno=");
// and so on...
If so can anyone please tell me what value "CURLOPT_PINNEDPUBLICKEY" actually has? In my
example above I used 1234 just as a placeholder.
Also will older curl version ignore the value or do I have to check whether the installed curl
version supports this constant?
------------------------------------------------------------------------
[2016-09-15 10:37:47] cmb@php.net
Improved the docs[1] and submitted a PR wrt. the error constant[2].
[1] <http://svn.php.net/viewvc?view=revision&revision=340038>
[2] <https://github.com/php/php-src/pull/2128>
------------------------------------------------------------------------
[2016-09-15 09:13:41] cmb@php.net
The option is actually called CULROPT_PINNEDPUBLICKEY, and it's
already basically documented. The docs need to be improved; see
<https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html>.
Also the error constant CURLE_SSL_PINNEDPUBKEYNOTMATCH has to be
implemented.
------------------------------------------------------------------------
[2016-09-14 21:38:02] rugk at posteo dot de
So how can this be used in PHP?
When will the doc (I assume https://secure.php.net/manual/de/function.curl-setopt.php)
be updated?
------------------------------------------------------------------------
[2016-07-03 16:56:54] cmb@php.net
> Asked in room 11, and Nikita says this should be as simple as
> defining the constant.
Indeed, and that has happened as of PHP 7.0.7.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68575
--
Edit this bug report at https://bugs.php.net/bug.php?id=68575&edit=1