note 121376 deleted from function.curl-setopt by crell

From: Date: Thu, 31 Mar 2022 20:55:57 +0000
Subject: note 121376 deleted from function.curl-setopt by crell
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-217985@lists.php.net to get a copy of this message
Note Submitter: chris at ocproducts dot com ---- On recent versions of MacOS CURLOPT_SSL_VERIFYPEER cannot be disabled, unless you have compiled PHP yourself with the official cURL library and OpenSSL. Why? 1) MacOS is bundling its own version of cURL which has Apple SecureTransport as the SSL handling. 2) The implementation will complain if CURLOPT_SSL_VERIFYPEER is disabled but CURLOPT_CAINFO is set ("CA certificate set, but certificate verification is disabled"). 3) The implementation will consider CURLOPT_CAINFO set even if it is set to blank/null/false ("can't load CA certificate file"). This error comes from ""SSL: can't load CA certificate file %s"" in https://opensource.apple.com/source/curl/curl-95/curl/lib/vtls/darwinssl.c, you can see there's no blank verification. To confirm this is what is affecting you look for what "SSL Version" is set at in the PHP-info. This is under the cURL settings. To resolve you need to compile cURL (e.g. using Homebrew) with OpenSSL enabled: brew install curl --with-openssl Then compile PHP with something like this in the configure command: '--with-curl=/usr/local/opt/curl' It may also be possible to use Homebrew to compile PHP using it's own cURL, I haven't checked this. Once resolved "SSL Version" will report something like "OpenSSL/1.0.2l". Of course you shouldn't disable certificate validation. I am only doing it because I'm writing code to detect if a site's SSL is broken (works with verify peer, doesn't work without). Others maybe are using self-signed certificates and don't want to work out how to make them a root authority. Never ever use live.

« previous php.notes (#217985) next »