#50336 [Tbd->Csd]: [TBD] for server name indication support in openssl

From: Date: Wed, 23 Dec 2009 16:18:27 +0000
Subject: #50336 [Tbd->Csd]: [TBD] for server name indication support in openssl
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-3541@lists.php.net to get a copy of this message
ID: 50336 Updated by: kalle@php.net Reported By: lbarnaud@php.net -Status: To be documented +Status: Closed Bug Type: Documentation problem PHP Version: 5.3SVN-2009-11-30 (snap) -Assigned To: +Assigned To: kalle New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2009-12-23 16:18:22] svn@php.net Automatic comment from SVN on behalf of kalle Revision: http://svn.php.net/viewvc/?view=revision&revision=292542 Log: Documented SNI support in OpenSSL from 5.3.2 (closes #50336) ------------------------------------------------------------------------ [2009-11-30 15:34:57] lbarnaud@php.net open -> tbd ------------------------------------------------------------------------ [2009-11-30 15:33:43] lbarnaud@php.net Description: ------------ Document sni support in openssl. Since 5.3.2. New SSL context options : - SNI_enabled : Set to FALSE to disable SNI support (enabled by default) - SNI_server_name : If not set, the server name will be guessed from the stream URL (e.g. https://example.com/ will use example.com as hostname.), else the given name will be used. SNI is to SSL/TLS what the Host header is to HTTP : it allows multiple certificates on the same IP address. As for HTTP virtual hosts, this should be totaly transparent in most cases. Context options allows more control, e.g. : $context = stream_context_create(array( 'ssl' => array('SNI_server_name' => 'foo.example.com'), 'http' => array('header' => 'Host: foo.example.com'), )); file_get_contents('https://127.0.0.1/', false, $context); OpenSSL >= 0.9.8j supports SNI (by default since OpenSSL 0.9.8k). New constant : OPENSSL_TLSEXT_SERVER_NAME is defined if there is support for SNI. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=50336&edit=1

« previous php.doc.bugs (#3541) next »