Req #79280 [Opn->Csd]: Add support for TLS-PSK

From: Date: Thu, 01 Oct 2026 20:26:39 +0000
Subject: Req #79280 [Opn->Csd]: Add support for TLS-PSK
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-252876@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79280&edit=1 ID: 79280 Updated by: bukka@php.net Reported by: php at tudorholton dot com Summary: Add support for TLS-PSK -Status: Open +Status: Closed Type: Feature/Change Request Package: OpenSSL related Operating System: Irrelevant PHP Version: Next Major Version -Assigned To: +Assigned To: bukka Block user comment: N Private report: N New Comment: This has been added to PHP 8.6 Previous Comments: ------------------------------------------------------------------------ [2021-08-09 14:23:36] cmb@php.net > I've asked if we can reopen the libcurl PR #394. :-) For reference: <https://github.com/curl/curl/issues/5081>. ------------------------------------------------------------------------ [2020-03-13 00:42:23] php at tudorholton dot com Alternatively, would PHP with libcurl->WolfSSL work? I haven't spent much time in configuring PHP, and my OS (Ubuntu) doesn't have a libcurl-wolfssl package, but I suppose it's possible to manually compile it. PHP would still need an option to pass to libcurl, though. It might be easier to compile a fork of libcurl-OpenSSL with the --tlk-psk switch enabled. ------------------------------------------------------------------------ [2020-03-12 02:26:26] php at tudorholton dot com Thanks Rowan, that's a great help. TSL-PSK support for OpenSSL for libcurl was discussed in 2015 but went stale. See here: https://github.com/curl/curl/pull/394 (Unrelated, but libcurl does support PSK via WolfSSL in their release version, so they're not against PSK itself, it seems.) I've asked if we can reopen the libcurl PR #394. :-) ------------------------------------------------------------------------ [2020-03-11 22:40:31] rowan dot collins at gmail dot com OK, looking at that library, it seems what they actually use to make HTTP requests is this library: https://github.com/zendframework/zend-http That in turn uses either PHP's curl bindings, or raw socket connections (with PHP's socket library providing the TLS encapsulation). So the PHP support which would be needed would be: - an option for the tls:// stream type, which is based on openssl: https://www.php.net/manual/en/context.ssl.php - an option in the curl bindings: https://www.php.net/manual/en/function.curl-setopt.php I don't know what support either openssl or libcurl have for this, so I can't comment further on how easy it would be to add. ------------------------------------------------------------------------ [2020-02-25 23:19:58] php at tudorholton dot com The request is for a connection from PHP as a client to a server where the connection is encrypted with TLS-PSK. Yes, a shared key needs to be supplied for the connection to work. I believe that this is similar to PHP as a TLS client with a client certificate except that there's a shared key in place of two separate certificates (and no third-party verifier). I've seen TLS-PSK used mainly in networks where a certificate authority is not available. BareOS comes with a "WebUI" client which is where I got the example from. The webui client source is here: https://github.com/bareos/bareos/tree/master/webui There is also a non-PHP (C++) client which successfully uses TLS-PSK here: https://github.com/bareos/bareos/tree/master/core/src/console Every other part of this system defaults to TLS-PSK. It's only the PHP part that can't do it, which is why I submit this bug request. Seems a bit odd to me. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=79280 -- Edit this bug report at https://bugs.php.net/bug.php?id=79280&edit=1

« previous php.bugs (#252876) next »