mirror of
https://github.com/curl/curl.git
synced 2026-08-24 18:23:33 +03:00
ssl: set engine implicitly when a PKCS#11 URI is provided
This allows the use of PKCS#11 URI for certificates and keys without setting the corresponding type as "ENG" and the engine as "pkcs11" explicitly. If a PKCS#11 URI is provided for certificate, key, proxy_certificate or proxy_key, the corresponding type is set as "ENG" if not provided and the engine is set to "pkcs11" if not provided. Acked-by: Nikos Mavrogiannopoulos Closes #2333
This commit is contained in:
parent
c892795ea3
commit
298d2565e2
6 changed files with 109 additions and 1 deletions
|
|
@ -23,6 +23,13 @@ nickname contains ":", it needs to be preceded by "\\" so that it is not
|
|||
recognized as password delimiter. If the nickname contains "\\", it needs to
|
||||
be escaped as "\\\\" so that it is not recognized as an escape character.
|
||||
|
||||
If curl is built against OpenSSL library, and the engine pkcs11 is available,
|
||||
then a PKCS#11 URI (RFC 7512) can be used to specify a certificate located in
|
||||
a PKCS#11 device. A string beginning with "pkcs11:" will be interpreted as a
|
||||
PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine option will be set
|
||||
as "pkcs11" if none was provided and the --cert-type option will be set as
|
||||
"ENG" if none was provided.
|
||||
|
||||
(iOS and macOS only) If curl is built against Secure Transport, then the
|
||||
certificate string can either be the name of a certificate/private key in the
|
||||
system or user keychain, or the path to a PKCS#12-encoded certificate and
|
||||
|
|
|
|||
|
|
@ -7,4 +7,11 @@ Private key file name. Allows you to provide your private key in this separate
|
|||
file. For SSH, if not specified, curl tries the following candidates in order:
|
||||
'~/.ssh/id_rsa', '~/.ssh/id_dsa', './id_rsa', './id_dsa'.
|
||||
|
||||
If curl is built against OpenSSL library, and the engine pkcs11 is available,
|
||||
then a PKCS#11 URI (RFC 7512) can be used to specify a private key located in a
|
||||
PKCS#11 device. A string beginning with "pkcs11:" will be interpreted as a
|
||||
PKCS#11 URI. If a PKCS#11 URI is provided, then the --engine option will be set
|
||||
as "pkcs11" if none was provided and the --key-type option will be set as
|
||||
"ENG" if none was provided.
|
||||
|
||||
If this option is used several times, the last one will be used.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue