[php-src] Issue #11944: Have cURL extension look for certificates in directory set by "openssl.capath"
| From: | CruelDrool | Date: | Fri, 11 Aug 2023 19:49:36 +0000 |
| Subject: | [php-src] Issue #11944: Have cURL extension look for certificates in directory set by "openssl.capath" | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245160@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/11944
Author: CruelDrool
### Description
I'm on Windows using
openssl.cafile and a cacert.pem from
[curl.se](https://curl.se) . I also got a local CA certificate that I use. So far I've been
just editing any new cacert.pem file to add my certificate. Been working great, but wanted to test
if cURL would use openssl.capath to look for it. However, it was just ignoring even
with the correct filname (<certificate hash>.0), not even making any access to
the directory I set. Only using CURLOPT_CAPATH in the PHP script made it look for the
certificate.
Checked out branch "PHP-8.1.22" and looked into ext/curl/interface.c and did
the following:
```diff
@@ -1817,6 +1817,7 @@ static void create_certinfo(struct curl_certinfo *ci, zval *listcode)
static void _php_curl_set_default_options(php_curl *ch)
{
char *cainfo;
+ char *capath;
curl_easy_setopt(ch->cp, CURLOPT_NOPROGRESS, 1);
curl_easy_setopt(ch->cp, CURLOPT_VERBOSE, 0);
@@ -1840,6 +1841,11 @@ static void _php_curl_set_default_options(php_curl *ch)
if (cainfo && cainfo[0] != '\0') {
curl_easy_setopt(ch->cp, CURLOPT_CAINFO, cainfo);
}
+
+ capath = INI_STR("openssl.capath");
+ if (capath && capath[0] != '\0') {
+ curl_easy_setopt(ch->cp, CURLOPT_CAPATH, capath);
+ }
#ifdef ZTS
curl_easy_setopt(ch->cp, CURLOPT_NOSIGNAL, 1);
```
Compiled and tested to be working.
Could also consider adding curl.capath as a setting.