Bug #77762 [Ver->Csd]: CURLOPT_SSL_VERIFYHOST should mention subjectaltname
| From: | git@php.net | Date: | Fri, 16 Jul 2021 15:15:20 +0000 |
| Subject: | Bug #77762 [Ver->Csd]: CURLOPT_SSL_VERIFYHOST should mention subjectaltname | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18963@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77762&edit=1
ID: 77762
Updated by: git@php.net
Reported by: hanno at hboeck dot de
Summary: CURLOPT_SSL_VERIFYHOST should mention subjectaltname
-Status: Verified
+Status: Closed
Type: Bug
Package: Documentation problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmb69
Revision: https://github.com/php/doc-en/commit/59e1af19dd3d3bac54ee03b0584ba18368693c01
Log: Fix #77762: CURLOPT_SSL_VERIFYHOST should mention subjectaltname
Previous Comments:
------------------------------------------------------------------------
[2019-03-18 12:13:13] hanno at hboeck dot de
Description:
------------
Under
http://php.net/curl_setopt
the description of CURLOPT_SSL_VERIFYHOST reads
" 1 to check the existence of a common name in the SSL peer certificate. 2 to check the
existence of a common name and also verify that it matches the hostname provided. 0 to not check the
names. In production environments the value of this option should be kept at 2 (default value).
"
The "common name" in a certificate is deprecated and the modern way of having hostnames in
certificates is the subjectaltname. The correct description would therefore be that it checks for
either the common name or the Subject Alternative Name. See also curl upstream docs:
https://curl.haxx.se/libcurl/c/CURLOPT_SSL_VERIFYHOST.html
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77762&edit=1