note 29427 deleted from ref.curl by betz

From: Date: Fri, 23 Apr 2004 08:42:50 +0000
Subject: note 29427 deleted from ref.curl by betz
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-68586@lists.php.net to get a copy of this message
Note Submitter: stain at dxml dot org ---- php 4.3.0 + curl 7.10.3 in my php code i do something like: <code> $ch = curl_init(); curl_setopt ($ch, CURLOPT_URL, 'https://www.example.com/path/to/file.ext'); ob_start(); curl_exec ($ch); ob_end_flush(); if (curl_error($ch)) printf("Error %s: %s", curl_errno($ch), curl_error($ch)); curl_close ($ch); </code> and i retrieve an error like: Error 35: SSL: error:xxxxxxxx:lib(xx):func(xxx):reason(xxx) curl error 35 is CURLE_SSL_CONNECT_ERROR from SSLCERTS file in curl source directory: "Starting in 7.10, libcurl performs peer SSL certificate verification by default. [...] If the remote server uses a self-signed certificate, or if you don't install curl's CA cert bundle or if it uses a certificate signed by a CA that isn't included in the bundle, then you need to do one of the following: 1. Tell libcurl to *not* verify the peer. With libcurl you disable with with curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, FALSE); With the curl command tool, you disable this with -k/--insecure. [...]" (i suggest to read all the info provided with curl distribution) so, in php, you need do the following: curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0); i would be sure my connection don't crash, but since i didn't find any other documentation available, i add also the following: curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0); from php manual: "CURLOPT_SSL_VERIFYHOST: Pass a long if CURL should verify the Common name of the peer certificate in the SSL handshake. A value of 1 denotes that we should check for the existence of the common name, a value of 2 denotes that we should make sure it matches the provided hostname. " HTH bye, stain.

« previous php.notes (#68586) next »