Bug #11587 Updated: SSL'd fsockopen would be nice
| From: | sebastian@php.net | Date: | Sun, 12 Aug 2001 19:28:53 +0000 |
| Subject: | Bug #11587 Updated: SSL'd fsockopen would be nice | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-63012@lists.php.net to get a copy of this message | ||
ID: 11587
Updated by: sebastian
Reported By: mitja@doticni.net
Old Status: Open
Status: Duplicate
Bug Type: Feature/Change Request
Operating System:
PHP Version: 4.0.5
New Comment:
This extends Bug #5865.
Previous Comments:
------------------------------------------------------------------------
[2001-06-20 14:18:10] mitja@doticni.net
While working on #5865, you could also add generic SSL socket support to fsockopen, something like
fsockopen("ssl://example.com", ...)
don't forget to add support for client certificates/keys, including passing the password to
unlock 'em (ok, this would probably require a completely new function).
for connecting to a single server, one solution is running a stunnel daemon:
stunnel -c -d 127.0.0.1:1000 -r example.com:123 -p /certs/blah.pem
and then fsockopen()ing to that port;
however, this is both a security problem (anyone on the machine can connect to that port) and
useless, if one wishes to connect to a host that is not known in advance.
another option would be to allow php to talk to exec'd processes (hopefully stunnel works this
way; it doesn't when piped), but this requires an extra process per request which is a resource
hog. and, well, this is all in openssl already, so ...
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=11587&edit=1