mirror of
https://github.com/curl/curl.git
synced 2026-07-25 18:37:17 +03:00
CURLOPT_PINNEDPUBLICKEY.md: does not apply for other origins
Clarify Closes #21885
This commit is contained in:
parent
f7f1666ee2
commit
38b72f3b56
1 changed files with 7 additions and 3 deletions
|
|
@ -36,9 +36,9 @@ CURLcode curl_easy_setopt(CURL *handle, CURLOPT_PINNEDPUBLICKEY,
|
|||
# DESCRIPTION
|
||||
|
||||
Pass a pointer to a null-terminated string as parameter. The string can be the
|
||||
filename of your pinned public key. The file format expected is "PEM" or
|
||||
"DER". The string can also be any number of base64 encoded sha256 hashes
|
||||
preceded by "sha256//" and separated by ";"
|
||||
filename of your pinned public key. The file format expected is `PEM` or
|
||||
`DER`. The string can also be any number of base64 encoded sha256 hashes
|
||||
preceded by `sha256//` and separated by `;`.
|
||||
|
||||
When negotiating a TLS or SSL connection, the server sends a certificate
|
||||
indicating its identity. A public key is extracted from this certificate and
|
||||
|
|
@ -53,6 +53,10 @@ On mismatch, *CURLE_SSL_PINNEDPUBKEYNOTMATCH* is returned.
|
|||
The application does not have to keep the string around after setting this
|
||||
option.
|
||||
|
||||
The pinned public key is used to verify the initial origin used in a transfer.
|
||||
If the transfer is set to follow redirects to other origins, they are *not*
|
||||
checked against this key.
|
||||
|
||||
This option has no effect on LDAP connections when libcurl uses the legacy LDAP
|
||||
backend. That backend manages TLS independently of curl's TLS layer. When
|
||||
libcurl is built with USE_OPENLDAP, the OpenLDAP backend routes TLS through
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue