#50336 [Opn->Tbd]: [TBD] for server name indication support in openssl
| From: | lbarnaud@php.net | Date: | Mon, 30 Nov 2009 15:34:58 +0000 |
| Subject: | #50336 [Opn->Tbd]: [TBD] for server name indication support in openssl | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3369@lists.php.net to get a copy of this message | ||
ID: 50336
Updated by: lbarnaud@php.net
Reported By: lbarnaud@php.net
-Status: Open
+Status: To be documented
Bug Type: Documentation problem
PHP Version: 5.3SVN-2009-11-30 (snap)
New Comment:
open -> tbd
Previous Comments:
------------------------------------------------------------------------
[2009-11-30 15:33:43] lbarnaud@php.net
Description:
------------
Document sni support in openssl.
Since 5.3.2.
New SSL context options :
- SNI_enabled : Set to FALSE to disable SNI support (enabled by
default)
- SNI_server_name : If not set, the server name will be guessed from
the stream URL (e.g. https://example.com/ will use example.com as
hostname.), else the given name will be used.
SNI is to SSL/TLS what the Host header is to HTTP : it allows multiple
certificates on the same IP address. As for HTTP virtual hosts, this
should be totaly transparent in most cases.
Context options allows more control, e.g. :
$context = stream_context_create(array(
'ssl' => array('SNI_server_name' => 'foo.example.com'),
'http' => array('header' => 'Host: foo.example.com'),
));
file_get_contents('https://127.0.0.1/', false,
$context);
OpenSSL >= 0.9.8j supports SNI (by default since OpenSSL 0.9.8k).
New constant :
OPENSSL_TLSEXT_SERVER_NAME is defined if there is support for SNI.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=50336&edit=1