#50336 [Tbd->Csd]: [TBD] for server name indication support in openssl
| From: | kalle@php.net | Date: | Wed, 23 Dec 2009 16:18:27 +0000 |
| Subject: | #50336 [Tbd->Csd]: [TBD] for server name indication support in openssl | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-3541@lists.php.net to get a copy of this message | ||
ID: 50336
Updated by: kalle@php.net
Reported By: lbarnaud@php.net
-Status: To be documented
+Status: Closed
Bug Type: Documentation problem
PHP Version: 5.3SVN-2009-11-30 (snap)
-Assigned To:
+Assigned To: kalle
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
Previous Comments:
------------------------------------------------------------------------
[2009-12-23 16:18:22] svn@php.net
Automatic comment from SVN on behalf of kalle
Revision: http://svn.php.net/viewvc/?view=revision&revision=292542
Log: Documented SNI support in OpenSSL from 5.3.2 (closes #50336)
------------------------------------------------------------------------
[2009-11-30 15:34:57] lbarnaud@php.net
open -> tbd
------------------------------------------------------------------------
[2009-11-30 15:33:43] lbarnaud@php.net
Description:
------------
Document sni support in openssl.
Since 5.3.2.
New SSL context options :
- SNI_enabled : Set to FALSE to disable SNI support (enabled by
default)
- SNI_server_name : If not set, the server name will be guessed from
the stream URL (e.g. https://example.com/ will use example.com as
hostname.), else the given name will be used.
SNI is to SSL/TLS what the Host header is to HTTP : it allows multiple
certificates on the same IP address. As for HTTP virtual hosts, this
should be totaly transparent in most cases.
Context options allows more control, e.g. :
$context = stream_context_create(array(
'ssl' => array('SNI_server_name' => 'foo.example.com'),
'http' => array('header' => 'Host: foo.example.com'),
));
file_get_contents('https://127.0.0.1/', false,
$context);
OpenSSL >= 0.9.8j supports SNI (by default since OpenSSL 0.9.8k).
New constant :
OPENSSL_TLSEXT_SERVER_NAME is defined if there is support for SNI.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=50336&edit=1