Req #81528 [Com]: Support multiple peer_fingerprint values per algorithm
Edit report at https://bugs.php.net/bug.php?id=81528&edit=1
ID: 81528
Comment by: kjshelen34 at gmail dot com
Reported by: david at mandelberg dot org
Summary: Support multiple peer_fingerprint values per
algorithm
Status: Open
Type: Feature/Change Request
Package: OpenSSL related
PHP Version: master-Git-2021-10-16 (Git)
Block user comment: N
Private report: N
New Comment:
That was so amazing.
(https://github.com)(https://www.tellpopeyes.biz/)
Previous Comments:
------------------------------------------------------------------------
[2021-10-16 01:12:51] david at mandelberg dot org
I don't think deducing the algorithm from the length is a good idea long-term, because there
are multiple good algorithms with the same output length. E.g., SHA-256 and SHA3-256.
------------------------------------------------------------------------
[2021-10-16 01:10:10] requinix@php.net
Or easier, change the array form to support non-string keys (or ignore keys entirely) and instead
deduce algorithm by the length - like it already does for the string form.
------------------------------------------------------------------------
[2021-10-16 00:54:58] david at mandelberg dot org
Description:
------------
Would it be possible to extend peer_fingerprint from https://www.php.net/manual/en/context.ssl.php
to support an array of multiple fingerprints per algorithm, instead of just one? I don't
currently see a way to configure secure certificate verification for a redundant service (where each
server has its own certificate) without using a CA.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81528&edit=1
Thread (4 messages)