mirror of
https://github.com/curl/curl.git
synced 2026-08-25 18:13:37 +03:00
TLS: remove support for Secure Transport and BearSSL
These libraries do not support TLS 1.3 and have been marked for removal for over a year. We want to help users select a TLS dependency that is future-proof and reliable, and not supporting TLS 1.3 in 2025 does not infer confidence. Users who build libcurl are likely to be served better and get something more future-proof with a TLS library that supports 1.3. Closes #16677
This commit is contained in:
parent
b761eb5add
commit
08a3e8e19a
89 changed files with 163 additions and 5036 deletions
|
|
@ -8,9 +8,9 @@ SPDX-License-Identifier: curl
|
|||
|
||||
## Native vs file based
|
||||
|
||||
If curl was built with Schannel or Secure Transport support, then curl uses
|
||||
the system native CA store for verification. All other TLS libraries use a
|
||||
file based CA store by default.
|
||||
If curl was built with Schannel support, then curl uses the system native CA
|
||||
store for verification. All other TLS libraries use a file based CA store by
|
||||
default.
|
||||
|
||||
## Verification
|
||||
|
||||
|
|
@ -102,17 +102,13 @@ latest Firefox bundle.
|
|||
|
||||
## Native CA store
|
||||
|
||||
If curl was built with Schannel, Secure Transport or were instructed to use
|
||||
the native CA Store, then curl uses the certificates that are built into the
|
||||
OS. These are the same certificates that appear in the Internet Options
|
||||
control panel (under Windows) or Keychain Access application (under macOS).
|
||||
Any custom security rules for certificates are honored.
|
||||
If curl was built with Schannel or was instructed to use the native CA Store,
|
||||
then curl uses the certificates that are built into the OS. These are the same
|
||||
certificates that appear in the Internet Options control panel (under Windows)
|
||||
or Keychain Access application (under macOS). Any custom security rules for
|
||||
certificates are honored.
|
||||
|
||||
Schannel runs CRL checks on certificates unless peer verification is disabled.
|
||||
Secure Transport on iOS runs OCSP checks on certificates unless peer
|
||||
verification is disabled. Secure Transport on macOS runs either OCSP or CRL
|
||||
checks on certificates if those features are enabled, and this behavior can be
|
||||
adjusted in the preferences of Keychain Access.
|
||||
|
||||
## HTTPS proxy
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue