mirror of
https://github.com/curl/curl.git
synced 2026-08-26 08:13:32 +03:00
windows: add build option to use the native CA store
With the same semantics as Apple SecTrust, in both libcurl and the curl tool, when using non-Schannel TLS backends. In practice it means that it makes TLS work without manually or implicitly configuring a CA bundle `.crt` file, such as `curl-ca-bundle.crt`. To enable: - autotools: `--enable-ca-native` - cmake: `-DCURL_CA_NATIVE=ON` - CPPFLAGS: `-DCURL_CA_NATIVE` When enabled: - enables `CURLSSLOPT_NATIVE_CA` (libcurl) / `--ca-native` and `--proxy-ca-native` (curl tool) options by default. - unsafe search for an on-disk CA bundle gets disabled by default. Equivalent to `--disable-ca-search` with autotools, `-DCURL_DISABLE_CA_SEARCH=ON` with CMake. - build-time detection of CA bundle and CA path gets disabled. As with Apple SecTrust. This was already the default for Windows. - native CA can be disabled at run-time with the `--no-ca-native` and/or `--no-proxy-ca-native` command-line options. Rationale: This build option: - has a repeat and active interest from packagers and users. - helps integrating curl with Windows for those who need this. - it also applies to macOS: #17525 Shipped in curl 8.17.0. - makes it trivial to use custom certs configured on the OS. - frees applications/packagers/users from the task of securely distributing, and keeping up-to-date, a CA bundle. - frees potentially many curl tool from configuring a CA bundle manually to access HTTPS (and other TLS) URLs. This is traditionally difficult on Windows because there is no concept of a universal, protected, non-world-writable, location on the file system to securely store a CA bundle. - allows using modern features regardless of Windows version. Some of these features are not supported with Schannel (e.g. HTTP/3, ECH) on any Windows version. - is necessary for HTTP/3 builds, where bootstrapping a CA bundle is not possible with Schannel, because MultiSSL is not an option, and HTTP/3 is not supported with Schannel. Ref: #16181 (previous attempt) Ref: https://github.com/curl/curl/discussions/9348 Ref: https://github.com/curl/curl/issues/9350 Ref: https://github.com/curl/curl/pull/13111 Ref: https://github.com/microsoft/vcpkg/pull/46459#issuecomment-3162068701 Ref:22652a5a4c#14582 Ref:eefd03c572#18703 Closes #18279
This commit is contained in:
parent
5aa303f1bf
commit
1730407b74
9 changed files with 83 additions and 13 deletions
|
|
@ -260,6 +260,8 @@ target_link_libraries(my_target PRIVATE CURL::libcurl)
|
|||
- `CURL_CA_BUNDLE`: Absolute path to the CA bundle. Set `none` to disable or `auto` for auto-detection. Default: `auto`
|
||||
- `CURL_CA_EMBED`: Absolute path to the CA bundle to embed in the curl tool. Default: (disabled)
|
||||
- `CURL_CA_FALLBACK`: Use built-in CA store of OpenSSL. Default: `OFF`
|
||||
- `CURL_CA_NATIVE`: Use native CA store. Default: `OFF`
|
||||
Supported by GnuTLS, OpenSSL (including forks) on Windows, wolfSSL.
|
||||
- `CURL_CA_PATH`: Absolute path to a directory containing CA certificates stored individually. Set `none` to disable or `auto` for auto-detection. Default: `auto`
|
||||
- `CURL_CA_SEARCH_SAFE`: Enable safe CA bundle search (within the curl tool directory) on Windows. Default: `OFF`
|
||||
|
||||
|
|
@ -283,7 +285,7 @@ target_link_libraries(my_target PRIVATE CURL::libcurl)
|
|||
- `CURL_DISABLE_BASIC_AUTH`: Disable Basic authentication. Default: `OFF`
|
||||
- `CURL_DISABLE_BEARER_AUTH`: Disable Bearer authentication. Default: `OFF`
|
||||
- `CURL_DISABLE_BINDLOCAL`: Disable local binding support. Default: `OFF`
|
||||
- `CURL_DISABLE_CA_SEARCH`: Disable unsafe CA bundle search in PATH on Windows. Default: `OFF`
|
||||
- `CURL_DISABLE_CA_SEARCH`: Disable unsafe CA bundle search in PATH on Windows. Default: `OFF` (turns to `ON`, when `CURL_CA_NATIVE=ON`)
|
||||
- `CURL_DISABLE_COOKIES`: Disable cookies support. Default: `OFF`
|
||||
- `CURL_DISABLE_DICT`: Disable DICT. Default: `OFF`
|
||||
- `CURL_DISABLE_DIGEST_AUTH`: Disable Digest authentication. Default: `OFF`
|
||||
|
|
|
|||
|
|
@ -286,6 +286,13 @@ supports HTTP deflate using libz
|
|||
libcurl was built with multiple SSL backends. For details, see
|
||||
curl_global_sslset(3).
|
||||
|
||||
## `NativeCA`
|
||||
|
||||
*features* mask bit: non-existent
|
||||
|
||||
libcurl was built to enable native CA store, to verify server certificates
|
||||
(Added in 8.19.0).
|
||||
|
||||
## `NTLM`
|
||||
|
||||
*features* mask bit: CURL_VERSION_NTLM
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue