Re: Re: Windows Peer Verification

From: Date: Tue, 04 Feb 2014 08:00:12 +0000
Subject: Re: Re: Windows Peer Verification
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.internals 
Request: Send a blank email to internals+get-72182@lists.php.net to get a copy of this message
On Tue, Feb 4, 2014 at 8:57 AM, Lester Caine <lester@lsces.co.uk> wrote: > Pierre Joye wrote: >>> >>> Security is not the >>> >only thing that is reliant nowadays on third party data? >> >> We bundle the TZ data and it is used on all supported platforms. So >> no, no platform lags behind other. Some distributions may patch the >> date extension to use the system TZ but then it is none of our >> business. > > > But that is the whole point here ... it's the same argument with CA file? If someone distributes a patched PHP, it is none of our business. And CA file on Windows is not the same issue as Windows do not have system CA files compatible with OpenSSL. Implementing a backend using windows keys store and SSL APIs would bring more issues and incompatibilities (user lever) than asking users to set an ini setting.

« previous php.internals (#72182) next »