Bug #11587: SSL'd fsockopen would be nice
| From: | mitja at doticni dot net | Date: | Wed, 20 Jun 2001 18:18:10 +0000 |
| Subject: | Bug #11587: SSL'd fsockopen would be nice | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-57441@lists.php.net to get a copy of this message | ||
From: mitja@doticni.net
Operating system:
PHP version: 4.0.5
PHP Bug Type: Feature/Change Request
Bug description: SSL'd fsockopen would be nice
While working on #5865, you could also add generic SSL socket support to fsockopen, something like
fsockopen("ssl://example.com", ...)
don't forget to add support for client certificates/keys, including passing the password to
unlock 'em (ok, this would probably require a completely new function).
for connecting to a single server, one solution is running a stunnel daemon:
stunnel -c -d 127.0.0.1:1000 -r example.com:123 -p /certs/blah.pem
and then fsockopen()ing to that port;
however, this is both a security problem (anyone on the machine can connect to that port) and
useless, if one wishes to connect to a host that is not known in advance.
another option would be to allow php to talk to exec'd processes (hopefully stunnel works this
way; it doesn't when piped), but this requires an extra process per request which is a resource
hog. and, well, this is all in openssl already, so ...
--
Edit Bug report at: http://bugs.php.net/?id=11587&edit=1