Re: Re: Re: PHP Crypt functions - security audit
| From: | Adam Harvey | Date: | Fri, 20 Sep 2013 00:48:26 +0000 |
| Subject: | Re: Re: Re: PHP Crypt functions - security audit | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69241@lists.php.net to get a copy of this message | ||
On 19 September 2013 17:41, Pierre Joye <pierre.php@gmail.com> wrote:
> It does when you use curl's win32 SSL support. That makes my previous
> point wrong as we do not compile it with this option but openssl (for
> cross platform compatibility reasons). But as the curl's ca file works
> just fine, everything is good.
>
> Would it make sense to share that option for openssl itself?
I think so, particularly if we did make peer validation the default.
Most Windows users would be happy to just use the system certificate
store, I would think, so that would be one less thing to configure
post-install.
Adam