Req #68575 [ReO]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support

From: Date: Sun, 18 Sep 2016 16:09:02 +0000
Subject: Req #68575 [ReO]: Upgrade cURL to at least 7.39.0 for pinnedpubkey support
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204113@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68575&edit=1 ID: 68575 Updated by: cmb@php.net Reported by: scott at arciszewski dot me Summary: Upgrade cURL to at least 7.39.0 for pinnedpubkey support Status: Re-Opened Type: Feature/Change Request Package: cURL related Operating System: All PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: Yes, you can define the constant manually for older PHP versions, if its supported by libcurl (the value is supposed to be 10230, but that might change). If CURLOPT_PINNEDPUBLICKEY is not available in recent PHP versions, either cURL is not available at all, or you have libcurl < 7.39.0. Previous Comments: ------------------------------------------------------------------------ [2016-09-18 12:15:05] rugk at posteo dot de Currently when I do php -r 'echo CURLOPT_PINNEDPUBLICKEY;' in PHP 7.0.10 or even PHP Nightly (7.2.0-dev) I only get: Notice: Use of undefined constant CURLOPT_PINNEDPUBLICKEY - assumed 'CURLOPT_PINNEDPUBLICKEY' in Command line code on line 1 ------------------------------------------------------------------------ [2016-09-18 12:06:53] rugk at posteo dot de Oh I meant "in PHP < 7.0.7" of course. ------------------------------------------------------------------------ [2016-09-18 12:06:03] rugk at posteo dot de So if it is just the constant definition, which was missing, am I right that I could manually define the constant CURLOPT_PINNEDPUBLICKEY in PHP > 7.0.7 to use it? <?php defined('CURLOPT_PINNEDPUBLICKEY') || define('CURLOPT_PINNEDPUBLICKEY', 1234); $ch = curl_init("https://example.com"); curl_setopt($ch, CURLOPT_PINNEDPUBLICKEY, "sha256//YhKJKSzoTt2b5FP18fvpHo7fJYqQCjAa3HWY3tvRMwE=;sha256//t62CeU2tQiqkexU74Gxa2eg7fRbEgoChTociMee9wno="); // and so on... If so can anyone please tell me what value "CURLOPT_PINNEDPUBLICKEY" actually has? In my example above I used 1234 just as a placeholder. Also will older curl version ignore the value or do I have to check whether the installed curl version supports this constant? ------------------------------------------------------------------------ [2016-09-15 10:37:47] cmb@php.net Improved the docs[1] and submitted a PR wrt. the error constant[2]. [1] <http://svn.php.net/viewvc?view=revision&revision=340038> [2] <https://github.com/php/php-src/pull/2128> ------------------------------------------------------------------------ [2016-09-15 09:13:41] cmb@php.net The option is actually called CULROPT_PINNEDPUBLICKEY, and it's already basically documented. The docs need to be improved; see <https://curl.haxx.se/libcurl/c/CURLOPT_PINNEDPUBLICKEY.html>. Also the error constant CURLE_SSL_PINNEDPUBKEYNOTMATCH has to be implemented. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68575 -- Edit this bug report at https://bugs.php.net/bug.php?id=68575&edit=1

« previous php.bugs (#204113) next »