note 121376 deleted from function.curl-setopt by crell
| From: | crell@php.net | Date: | Thu, 31 Mar 2022 20:55:57 +0000 |
| Subject: | note 121376 deleted from function.curl-setopt by crell | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-217985@lists.php.net to get a copy of this message | ||
Note Submitter: chris at ocproducts dot com
----
On recent versions of MacOS CURLOPT_SSL_VERIFYPEER cannot be disabled, unless you have compiled PHP
yourself with the official cURL library and OpenSSL.
Why?
1) MacOS is bundling its own version of cURL which has Apple SecureTransport as the SSL handling.
2) The implementation will complain if CURLOPT_SSL_VERIFYPEER is disabled but CURLOPT_CAINFO is set
("CA certificate set, but certificate verification is disabled").
3) The implementation will consider CURLOPT_CAINFO set even if it is set to blank/null/false
("can't load CA certificate file"). This error comes from ""SSL:
can't load CA certificate file %s"" in https://opensource.apple.com/source/curl/curl-95/curl/lib/vtls/darwinssl.c,
you can see there's no blank verification.
To confirm this is what is affecting you look for what "SSL Version" is set at in the
PHP-info. This is under the cURL settings.
To resolve you need to compile cURL (e.g. using Homebrew) with OpenSSL enabled:
brew install curl --with-openssl
Then compile PHP with something like this in the configure command:
'--with-curl=/usr/local/opt/curl'
It may also be possible to use Homebrew to compile PHP using it's own cURL, I haven't
checked this.
Once resolved "SSL Version" will report something like "OpenSSL/1.0.2l".
Of course you shouldn't disable certificate validation. I am only doing it because I'm
writing code to detect if a site's SSL is broken (works with verify peer, doesn't work
without). Others maybe are using self-signed certificates and don't want to work out how to
make them a root authority. Never ever use live.