note 29427 deleted from ref.curl by betz
| From: | betz@php.net | Date: | Fri, 23 Apr 2004 08:42:50 +0000 |
| Subject: | note 29427 deleted from ref.curl by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-68586@lists.php.net to get a copy of this message | ||
Note Submitter: stain at dxml dot org
----
php 4.3.0 + curl 7.10.3
in my php code i do something like:
<code>
$ch = curl_init();
curl_setopt ($ch, CURLOPT_URL, 'https://www.example.com/path/to/file.ext');
ob_start();
curl_exec ($ch);
ob_end_flush();
if (curl_error($ch))
printf("Error %s: %s", curl_errno($ch), curl_error($ch));
curl_close ($ch);
</code>
and i retrieve an error like:
Error 35: SSL: error:xxxxxxxx:lib(xx):func(xxx):reason(xxx)
curl error 35 is CURLE_SSL_CONNECT_ERROR
from SSLCERTS file in curl source directory:
"Starting in 7.10, libcurl performs peer SSL certificate verification by
default.
[...]
If the remote server uses a self-signed certificate, or if you don't install
curl's CA cert bundle or if it uses a certificate signed by a CA that isn't
included in the bundle, then you need to do one of the following:
1. Tell libcurl to *not* verify the peer. With libcurl you disable with with
curl_easy_setopt(curl, CURLOPT_SSL_VERIFYPEER, FALSE);
With the curl command tool, you disable this with -k/--insecure.
[...]"
(i suggest to read all the info provided with curl distribution)
so, in php, you need do the following:
curl_setopt ($ch, CURLOPT_SSL_VERIFYPEER, 0);
i would be sure my connection don't crash, but since i didn't find any other
documentation available, i add also the following:
curl_setopt ($ch, CURLOPT_SSL_VERIFYHOST, 0);
from php manual:
"CURLOPT_SSL_VERIFYHOST: Pass a long if CURL should verify the Common name of the peer
certificate in the SSL handshake. A value of 1 denotes that we should check for the existence of the
common name, a value of 2 denotes that we should make sure it matches the provided hostname. "
HTH
bye, stain.