mirror of
https://github.com/curl/curl.git
synced 2026-08-25 20:33:35 +03:00
parent
8b7cbe9dec
commit
7c8bae0d9c
74 changed files with 117 additions and 3159 deletions
|
|
@ -6,19 +6,6 @@ email the
|
|||
as soon as possible and explain to us why this is a problem for you and
|
||||
how your use case cannot be satisfied properly using a workaround.
|
||||
|
||||
## NSS
|
||||
|
||||
We remove support for building curl with the NSS TLS library in August 2023.
|
||||
|
||||
- There are few users left who use curl+NSS
|
||||
- NSS has few users outside of curl as well (primarily Firefox)
|
||||
- NSS is harder than ever to find documentation for
|
||||
- NSS was always "best" used with Red Hat Linux when they provided additional
|
||||
features on top of the regular NSS that is not shipped by the vanilla library
|
||||
|
||||
Starting in 7.82.0, building curl to use NSS configure requires the additional
|
||||
flag `--with-nss-deprecated` in an attempt to highlight these plans.
|
||||
|
||||
## gskit
|
||||
|
||||
We remove support for building curl with the gskit TLS library in August 2023.
|
||||
|
|
@ -69,3 +56,4 @@ curl will remove the support for space-separated names in July 2024.
|
|||
- PolarSSL
|
||||
- NPN
|
||||
- Support for systems without 64 bit data types
|
||||
- NSS
|
||||
|
|
|
|||
10
docs/FAQ
10
docs/FAQ
|
|
@ -422,10 +422,10 @@ FAQ
|
|||
backends.
|
||||
|
||||
curl can be built to use one of the following SSL alternatives: OpenSSL,
|
||||
libressl, BoringSSL, AWS-LC, GnuTLS, wolfSSL, NSS, mbedTLS, Secure
|
||||
Transport (native iOS/OS X), Schannel (native Windows), GSKit (native IBM
|
||||
i), BearSSL, or Rustls. They all have their pros and cons, and we try to
|
||||
maintain a comparison of them here: https://curl.se/docs/ssl-compared.html
|
||||
libressl, BoringSSL, AWS-LC, GnuTLS, wolfSSL, mbedTLS, Secure Transport
|
||||
(native iOS/OS X), Schannel (native Windows), GSKit (native IBM i), BearSSL,
|
||||
or Rustls. They all have their pros and cons, and we try to maintain a
|
||||
comparison of them here: https://curl.se/docs/ssl-compared.html
|
||||
|
||||
2.4 Does curl support SOCKS (RFC 1928) ?
|
||||
|
||||
|
|
@ -902,7 +902,7 @@ FAQ
|
|||
|
||||
4.9 curl cannot authenticate to a server that requires NTLM?
|
||||
|
||||
NTLM support requires OpenSSL, GnuTLS, mbedTLS, NSS, Secure Transport, or
|
||||
NTLM support requires OpenSSL, GnuTLS, mbedTLS, Secure Transport, or
|
||||
Microsoft Windows libraries at build-time to provide this functionality.
|
||||
|
||||
4.10 My HTTP request using HEAD, PUT or DELETE does not work
|
||||
|
|
|
|||
|
|
@ -212,7 +212,7 @@
|
|||
6. requires c-ares
|
||||
7. requires libssh2, libssh or wolfSSH
|
||||
8. requires libssh2 or libssh
|
||||
9. requires OpenSSL, GnuTLS, mbedTLS, NSS, Secure Transport or SSPI
|
||||
9. requires OpenSSL, GnuTLS, mbedTLS, Secure Transport or SSPI
|
||||
(native Windows)
|
||||
10. requires libidn2 or Windows
|
||||
11. requires libz, brotli and/or zstd
|
||||
|
|
|
|||
|
|
@ -430,3 +430,8 @@ April: added the cyassl backend (later renamed to WolfSSL)
|
|||
|
||||
The curl.se website serves 16,500 GB/month over 462M requests, the
|
||||
official docker image has been pulled 4,098,015,431 times.
|
||||
|
||||
2023
|
||||
----
|
||||
|
||||
August: Dropped support for the NSS library
|
||||
|
|
|
|||
|
|
@ -7,7 +7,7 @@ HTTP/2 with curl
|
|||
Build prerequisites
|
||||
-------------------
|
||||
- nghttp2
|
||||
- OpenSSL, libressl, BoringSSL, NSS, GnuTLS, mbedTLS, wolfSSL or Schannel
|
||||
- OpenSSL, libressl, BoringSSL, GnuTLS, mbedTLS, wolfSSL or Schannel
|
||||
with a new enough version.
|
||||
|
||||
[nghttp2](https://nghttp2.org/)
|
||||
|
|
|
|||
|
|
@ -25,7 +25,7 @@ Current flaws in the curl CMake build
|
|||
|
||||
- Builds libcurl without large file support
|
||||
- Does not support all SSL libraries (only OpenSSL, Schannel,
|
||||
Secure Transport, and mbed TLS, NSS, WolfSSL)
|
||||
Secure Transport, and mbedTLS, WolfSSL)
|
||||
- Does not allow different resolver backends (no c-ares build support)
|
||||
- No RTMP support built
|
||||
- Does not allow build curl and libcurl debug enabled
|
||||
|
|
|
|||
|
|
@ -134,7 +134,6 @@ These options are provided to select the TLS backend to use.
|
|||
- BearSSL: `--with-bearssl`
|
||||
- GnuTLS: `--with-gnutls`.
|
||||
- mbedTLS: `--with-mbedtls`
|
||||
- NSS: `--with-nss`
|
||||
- OpenSSL: `--with-openssl` (also for BoringSSL, AWS-LC, libressl, and quictls)
|
||||
- rustls: `--with-rustls`
|
||||
- Schannel: `--with-schannel`
|
||||
|
|
|
|||
|
|
@ -28,7 +28,6 @@ versions of libs and build tools.
|
|||
- OpenLDAP 2.0
|
||||
- MIT Kerberos 1.2.4
|
||||
- GSKit V5R3M0
|
||||
- NSS 3.14.x
|
||||
- Heimdal ?
|
||||
- nghttp2 1.15.0
|
||||
- WinSock 2.2 (on Windows 95+ and Windows CE .NET 4.1+)
|
||||
|
|
|
|||
|
|
@ -83,7 +83,6 @@ problems may have been fixed or changed somewhat since this was written.
|
|||
12.1 OpenLDAP hangs after returning results
|
||||
12.2 LDAP on Windows does authentication wrong?
|
||||
12.3 LDAP on Windows does not work
|
||||
12.4 LDAPS with NSS is slow
|
||||
|
||||
13. TCP/IP
|
||||
13.2 Trying local ports fails on Windows
|
||||
|
|
@ -504,10 +503,6 @@ problems may have been fixed or changed somewhat since this was written.
|
|||
|
||||
https://github.com/curl/curl/issues/4261
|
||||
|
||||
12.4 LDAPS with NSS is slow
|
||||
|
||||
See https://github.com/curl/curl/issues/5874
|
||||
|
||||
13. TCP/IP
|
||||
|
||||
13.2 Trying local ports fails on Windows
|
||||
|
|
|
|||
|
|
@ -127,26 +127,6 @@ certificate store, will cause SSL to report an error ("certificate verify
|
|||
failed") during the handshake and SSL will then refuse further communication
|
||||
with that server.
|
||||
|
||||
Certificate Verification with NSS
|
||||
---------------------------------
|
||||
|
||||
If libcurl was built with NSS support, then depending on the OS distribution,
|
||||
it is probably required to take some additional steps to use the system-wide
|
||||
CA cert db. Red Hat ships with an additional module, libnsspem.so, which
|
||||
enables NSS to read the OpenSSL PEM CA bundle. On openSUSE you can install
|
||||
p11-kit-nss-trust which makes NSS use the system wide CA certificate
|
||||
store. NSS also has a new [database
|
||||
format](https://wiki.mozilla.org/NSS_Shared_DB).
|
||||
|
||||
Starting with version 7.19.7, libcurl automatically adds the `sql:` prefix to
|
||||
the certificate database directory (either the set default `/etc/pki/nssdb` or
|
||||
the directory configured with the `SSL_DIR` environment variable). To check
|
||||
which certificate database format your distribution provides, examine the
|
||||
default certificate database location: `/etc/pki/nssdb`; the new certificate
|
||||
database format can be identified by the filenames `cert9.db`, `key4.db`,
|
||||
`pkcs11.txt`; filenames of older versions are `cert8.db`, `key3.db`,
|
||||
`secmod.db`.
|
||||
|
||||
Certificate Verification with Schannel and Secure Transport
|
||||
-----------------------------------------------------------
|
||||
|
||||
|
|
|
|||
|
|
@ -23,9 +23,6 @@ The windows version of curl will automatically look for a CA certs file named
|
|||
'curl-ca-bundle.crt', either in the same directory as curl.exe, or in the
|
||||
Current Working Directory, or in any folder along your PATH.
|
||||
|
||||
If curl is built against the NSS SSL library, the NSS PEM PKCS#11 module
|
||||
(libnsspem.so) needs to be available for this option to work properly.
|
||||
|
||||
(iOS and macOS only) If curl is built against Secure Transport, then this
|
||||
option is supported for backward compatibility with other SSL engines, but it
|
||||
should not be set. If the option is not set, then curl will use the
|
||||
|
|
|
|||
|
|
@ -16,4 +16,4 @@ If this option is enabled and the server sends an invalid (e.g. expired)
|
|||
response, if the response suggests that the server certificate has been
|
||||
revoked, or no response at all is received, the verification fails.
|
||||
|
||||
This is currently only implemented in the OpenSSL, GnuTLS and NSS backends.
|
||||
This is currently only implemented in the OpenSSL and GnuTLS backends.
|
||||
|
|
|
|||
|
|
@ -24,15 +24,6 @@ as "\\:" so that it is not recognized as the password delimiter. Similarly, you
|
|||
must escape the character "\\" as "\\\\" so that it is not recognized as an
|
||||
escape character.
|
||||
|
||||
If curl is built against the NSS SSL library then this option can tell
|
||||
curl the nickname of the certificate to use within the NSS database defined
|
||||
by the environment variable SSL_DIR (or by default /etc/pki/nssdb). If the
|
||||
NSS PEM PKCS#11 module (libnsspem.so) is available then PEM files may be
|
||||
loaded.
|
||||
|
||||
If you provide a path relative to the current directory, you must prefix the
|
||||
path with "./" in order to avoid confusion with an NSS database nickname.
|
||||
|
||||
If curl is built against OpenSSL library, and the engine pkcs11 is available,
|
||||
then a PKCS#11 URI (RFC 7512) can be used to specify a certificate located in
|
||||
a PKCS#11 device. A string beginning with "pkcs11:" will be interpreted as a
|
||||
|
|
|
|||
|
|
@ -14,5 +14,5 @@ where a TLS client will start sending application data before verifying the
|
|||
server's Finished message, thus saving a round trip when performing a full
|
||||
handshake.
|
||||
|
||||
This is currently only implemented in the NSS and Secure Transport (on iOS 7.0
|
||||
or later, or OS X 10.9 or later) backends.
|
||||
This is currently only implemented in the Secure Transport (on iOS 7.0 or
|
||||
later, or OS X 10.9 or later) backend.
|
||||
|
|
|
|||
|
|
@ -82,7 +82,7 @@ If you set this environment variable to a file name, curl will store TLS
|
|||
secrets from its connections in that file when invoked to enable you to
|
||||
analyze the TLS traffic in real time using network analyzing tools such as
|
||||
Wireshark. This works with the following TLS backends: OpenSSL, libressl,
|
||||
BoringSSL, GnuTLS, NSS and wolfSSL.
|
||||
BoringSSL, GnuTLS and wolfSSL.
|
||||
.IP "USERPROFILE <dir>"
|
||||
On Windows, this variable is used when trying to find the home directory. If
|
||||
the other, primary, variable are all unset. If set, curl will use the path
|
||||
|
|
|
|||
|
|
@ -25,13 +25,13 @@ PEM/DER support:
|
|||
|
||||
7.39.0: OpenSSL, GnuTLS and GSKit
|
||||
|
||||
7.43.0: NSS and wolfSSL
|
||||
7.43.0: wolfSSL
|
||||
|
||||
7.47.0: mbedtls
|
||||
|
||||
sha256 support:
|
||||
|
||||
7.44.0: OpenSSL, GnuTLS, NSS and wolfSSL
|
||||
7.44.0: OpenSSL, GnuTLS and wolfSSL
|
||||
|
||||
7.47.0: mbedtls
|
||||
|
||||
|
|
|
|||
|
|
@ -21,7 +21,7 @@ Unix domain sockets are supported for socks proxy. Set localhost for the host
|
|||
part. e.g. socks5h://localhost/path/to/socket.sock
|
||||
|
||||
HTTPS proxy support via https:// protocol prefix was added in 7.52.0 for
|
||||
OpenSSL, GnuTLS and NSS. Since 7.87.0, it also works for BearSSL, mbedTLS,
|
||||
OpenSSL and GnuTLS. Since 7.87.0, it also works for BearSSL, mbedTLS,
|
||||
rustls, Schannel, Secure Transport and wolfSSL.
|
||||
|
||||
Unrecognized and unsupported proxy protocols cause an error since 7.52.0.
|
||||
|
|
|
|||
|
|
@ -41,7 +41,7 @@ The variables available are:
|
|||
.TP 15
|
||||
.B certs
|
||||
Output the certificate chain with details. Supported only by the OpenSSL,
|
||||
GnuTLS, Schannel, NSS, GSKit and Secure Transport backends. (Added in 7.88.0)
|
||||
GnuTLS, Schannel, GSKit and Secure Transport backends. (Added in 7.88.0)
|
||||
.TP
|
||||
.B content_type
|
||||
The Content-Type of the requested document, if there was any.
|
||||
|
|
@ -97,7 +97,7 @@ The http method used in the most recent HTTP request. (Added in 7.72.0)
|
|||
.TP
|
||||
.B num_certs
|
||||
Number of server certificates received in the TLS handshake. Supported only by
|
||||
the OpenSSL, GnuTLS, Schannel, NSS, GSKit and Secure Transport backends. (Added
|
||||
the OpenSSL, GnuTLS, Schannel, GSKit and Secure Transport backends. (Added
|
||||
in 7.88.0)
|
||||
.TP
|
||||
.B num_connects
|
||||
|
|
|
|||
|
|
@ -74,9 +74,6 @@ When set and libcurl runs with a SSL backend that supports this feature,
|
|||
libcurl will save SSL secrets into the given file name. Using those SSL
|
||||
secrets, other tools (such as Wireshark) can decrypt the SSL communication and
|
||||
analyze/view the traffic.
|
||||
.IP SSL_DIR
|
||||
When libcurl runs with the NSS backends for TLS features, this variable is
|
||||
used to find the directory for NSS PKI database instead of the built-in.
|
||||
.IP USER
|
||||
User name to use when invoking the \fIntlm-wb\fP tool, if \fINTLMUSER\fP and
|
||||
\fILOGNAME\fP were not set.
|
||||
|
|
|
|||
|
|
@ -75,8 +75,8 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
This option is only working in libcurl built with OpenSSL, NSS, Schannel, GSKit
|
||||
or Secure Transport support. Schannel support added in 7.50.0. Secure Transport
|
||||
This option is only working in libcurl built with OpenSSL, Schannel, GSKit or
|
||||
Secure Transport support. Schannel support added in 7.50.0. Secure Transport
|
||||
support added in 7.79.0.
|
||||
|
||||
Added in 7.19.1
|
||||
|
|
|
|||
|
|
@ -55,7 +55,7 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
Added in 7.5. Only set by the OpenSSL/libressl/boringssl, NSS and GnuTLS backends.
|
||||
Added in 7.5. Only set by the OpenSSL/libressl/boringssl and GnuTLS backends.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if the option is supported, and CURLE_UNKNOWN_OPTION if not.
|
||||
.SH "SEE ALSO"
|
||||
|
|
|
|||
|
|
@ -42,14 +42,6 @@ accessible file.
|
|||
This option is by default set to the system path where libcurl's CA
|
||||
certificate bundle is assumed to be stored, as established at build time.
|
||||
|
||||
If curl is built against the NSS SSL library, the NSS PEM PKCS#11 module
|
||||
(libnsspem.so) needs to be available for this option to work properly.
|
||||
Starting with curl 7.55.0, if both \fICURLOPT_CAINFO(3)\fP and
|
||||
\fICURLOPT_CAPATH(3)\fP are unset, NSS-linked libcurl tries to load
|
||||
libnssckbi.so, which contains a more comprehensive set of trust information
|
||||
than supported by nss-pem, because libnssckbi.so also includes information
|
||||
about distrusted certificates.
|
||||
|
||||
(iOS and macOS) When curl uses Secure Transport this option is supported. If
|
||||
the option is not set, then curl will use the certificates in the system and
|
||||
user Keychain to verify the peer.
|
||||
|
|
|
|||
|
|
@ -61,7 +61,7 @@ if(curl) {
|
|||
.fi
|
||||
.SH AVAILABILITY
|
||||
This option is supported by the OpenSSL, GnuTLS and mbedTLS (since 7.56.0)
|
||||
backends. The NSS backend provides the option only for backward compatibility.
|
||||
backends.
|
||||
.SH RETURN VALUE
|
||||
CURLE_OK if supported; or an error such as:
|
||||
|
||||
|
|
|
|||
|
|
@ -74,9 +74,9 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
This option is supported by the OpenSSL, GnuTLS, Schannel, NSS, GSKit and
|
||||
Secure Transport backends. Schannel support added in 7.50.0. Secure Transport
|
||||
support added in 7.79.0.
|
||||
This option is supported by the OpenSSL, GnuTLS, Schannel, GSKit and Secure
|
||||
Transport backends. Schannel support added in 7.50.0. Secure Transport support
|
||||
added in 7.79.0.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if the option is supported, and CURLE_UNKNOWN_OPTION if not.
|
||||
.SH "SEE ALSO"
|
||||
|
|
|
|||
|
|
@ -36,8 +36,8 @@ Pass a char * to a null-terminated string naming a \fIfile\fP with the
|
|||
concatenation of CRL (in PEM format) to use in the certificate validation that
|
||||
occurs during the SSL exchange.
|
||||
|
||||
When curl is built to use NSS or GnuTLS, there is no way to influence the use
|
||||
of CRL passed to help in the verification process.
|
||||
When curl is built to use GnuTLS, there is no way to influence the use of CRL
|
||||
passed to help in the verification process.
|
||||
|
||||
When libcurl is built with OpenSSL support, X509_V_FLAG_CRL_CHECK and
|
||||
X509_V_FLAG_CRL_CHECK_ALL are both set, requiring CRL check against all the
|
||||
|
|
|
|||
|
|
@ -55,10 +55,7 @@ When the \fIverify\fP value is set to 0L, the connection succeeds regardless of
|
|||
the names used in the certificate. Use that ability with caution!
|
||||
|
||||
See also \fICURLOPT_DOH_SSL_VERIFYPEER(3)\fP to verify the digital signature
|
||||
of the DoH server certificate. If libcurl is built against NSS and
|
||||
\fICURLOPT_DOH_SSL_VERIFYPEER(3)\fP is zero,
|
||||
\fICURLOPT_DOH_SSL_VERIFYHOST(3)\fP is also set to zero and cannot be
|
||||
overridden.
|
||||
of the DoH server certificate.
|
||||
.SH DEFAULT
|
||||
2
|
||||
.SH PROTOCOLS
|
||||
|
|
|
|||
|
|
@ -63,8 +63,8 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
Added in 7.76.0. This option is currently only supported by the OpenSSL, GnuTLS
|
||||
and NSS TLS backends.
|
||||
Added in 7.76.0. This option is currently only supported by the OpenSSL, and
|
||||
GnuTLS TLS backends.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if OCSP stapling is supported by the SSL backend, otherwise
|
||||
returns CURLE_NOT_BUILT_IN.
|
||||
|
|
|
|||
|
|
@ -73,7 +73,7 @@ HTTP NTLM authentication. A proprietary protocol invented and used by
|
|||
Microsoft. It uses a challenge-response and hash concept similar to Digest, to
|
||||
prevent the password from being eavesdropped.
|
||||
|
||||
You need to build libcurl with either OpenSSL, GnuTLS or NSS support for this
|
||||
You need to build libcurl with either OpenSSL or GnuTLS support for this
|
||||
option to work, or build libcurl on Windows with SSPI support.
|
||||
.IP CURLAUTH_NTLM_WB
|
||||
NTLM delegating to winbind helper. Authentication is performed by a separate
|
||||
|
|
|
|||
|
|
@ -104,7 +104,7 @@ PEM/DER support:
|
|||
|
||||
7.39.0-7.48.0,7.58.1+: GSKit
|
||||
|
||||
7.43.0: NSS and wolfSSL
|
||||
7.43.0: wolfSSL
|
||||
|
||||
7.47.0: mbedTLS
|
||||
|
||||
|
|
@ -114,7 +114,7 @@ PEM/DER support:
|
|||
|
||||
sha256 support:
|
||||
|
||||
7.44.0: OpenSSL, GnuTLS, NSS and wolfSSL
|
||||
7.44.0: OpenSSL, GnuTLS and wolfSSL
|
||||
|
||||
7.47.0: mbedTLS
|
||||
|
||||
|
|
|
|||
|
|
@ -48,7 +48,7 @@ proxy is used.
|
|||
.IP http://
|
||||
HTTP Proxy. Default when no scheme or proxy type is specified.
|
||||
.IP https://
|
||||
HTTPS Proxy. (Added in 7.52.0 for OpenSSL, GnuTLS and NSS. Since 7.87.0, it
|
||||
HTTPS Proxy. (Added in 7.52.0 for OpenSSL and GnuTLS Since 7.87.0, it
|
||||
also works for BearSSL, mbedTLS, rustls, Schannel, Secure Transport and
|
||||
wolfSSL.)
|
||||
|
||||
|
|
@ -123,9 +123,6 @@ Since 7.21.7 the proxy string supports the socks protocols as "schemes".
|
|||
|
||||
Since 7.50.2, unsupported schemes in proxy strings cause libcurl to return
|
||||
error.
|
||||
|
||||
curl built to use NSS cannot connect to an HTTPS server over a unix domain
|
||||
socket.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if proxies are supported, CURLE_UNKNOWN_OPTION if not, or
|
||||
CURLE_OUT_OF_MEMORY if there was insufficient heap space.
|
||||
|
|
|
|||
|
|
@ -38,7 +38,7 @@ Pass one of the values below to set the type of the proxy.
|
|||
.IP CURLPROXY_HTTP
|
||||
HTTP Proxy. Default.
|
||||
.IP CURLPROXY_HTTPS
|
||||
HTTPS Proxy using HTTP/1. (Added in 7.52.0 for OpenSSL, GnuTLS and NSS. Since
|
||||
HTTPS Proxy using HTTP/1. (Added in 7.52.0 for OpenSSL and GnuTLS. Since
|
||||
7.87.0, it also works for BearSSL, mbedTLS, rustls, Schannel, Secure Transport
|
||||
and wolfSSL.)
|
||||
.IP CURLPROXY_HTTPS2
|
||||
|
|
|
|||
|
|
@ -44,9 +44,6 @@ accessible file.
|
|||
This option is by default set to the system path where libcurl's CA
|
||||
certificate bundle is assumed to be stored, as established at build time.
|
||||
|
||||
If curl is built against the NSS SSL library, the NSS PEM PKCS#11 module
|
||||
(libnsspem.so) needs to be available for this option to work properly.
|
||||
|
||||
(iOS and macOS only) If curl is built against Secure Transport, then this
|
||||
option is supported for backward compatibility with other SSL engines, but it
|
||||
should not be set. If the option is not set, then curl will use the
|
||||
|
|
|
|||
|
|
@ -62,7 +62,7 @@ if(curl) {
|
|||
Added in 7.52.0
|
||||
|
||||
This option is supported by the OpenSSL, GnuTLS, and mbedTLS (since 7.56.0)
|
||||
backends. The NSS backend provides the option only for backward compatibility.
|
||||
backends.
|
||||
.SH RETURN VALUE
|
||||
CURLE_OK if supported; or an error such as:
|
||||
|
||||
|
|
|
|||
|
|
@ -38,11 +38,11 @@ Pass a char * to a null-terminated string naming a \fIfile\fP with the
|
|||
concatenation of CRL (in PEM format) to use in the certificate validation that
|
||||
occurs during the SSL exchange.
|
||||
|
||||
When curl is built to use NSS or GnuTLS, there is no way to influence the use
|
||||
of CRL passed to help in the verification process. When libcurl is built with
|
||||
OpenSSL support, X509_V_FLAG_CRL_CHECK and X509_V_FLAG_CRL_CHECK_ALL are both
|
||||
set, requiring CRL check against all the elements of the certificate chain if
|
||||
a CRL file is passed.
|
||||
When curl is built to use GnuTLS, there is no way to influence the use of CRL
|
||||
passed to help in the verification process. When libcurl is built with OpenSSL
|
||||
support, X509_V_FLAG_CRL_CHECK and X509_V_FLAG_CRL_CHECK_ALL are both set,
|
||||
requiring CRL check against all the elements of the certificate chain if a CRL
|
||||
file is passed.
|
||||
|
||||
This option makes sense only when used in combination with the
|
||||
\fICURLOPT_PROXY_SSL_VERIFYPEER(3)\fP option.
|
||||
|
|
|
|||
|
|
@ -98,11 +98,11 @@ footer:
|
|||
.SH AVAILABILITY
|
||||
PEM/DER support:
|
||||
|
||||
7.52.0: GSKit, GnuTLS, NSS, OpenSSL, mbedTLS, wolfSSL
|
||||
7.52.0: GSKit, GnuTLS, OpenSSL, mbedTLS, wolfSSL
|
||||
|
||||
sha256 support:
|
||||
|
||||
7.52.0: GnuTLS, NSS, OpenSSL, mbedTLS, wolfSSL
|
||||
7.52.0: GnuTLS, OpenSSL, mbedTLS, wolfSSL
|
||||
|
||||
Other SSL backends not supported.
|
||||
.SH RETURN VALUE
|
||||
|
|
|
|||
|
|
@ -39,10 +39,10 @@ the file name of your client certificate used to connect to the HTTPS proxy.
|
|||
The default format is "P12" on Secure Transport and "PEM" on other engines,
|
||||
and can be changed with \fICURLOPT_PROXY_SSLCERTTYPE(3)\fP.
|
||||
|
||||
With NSS or Secure Transport, this can also be the nickname of the certificate
|
||||
you wish to authenticate with as it is named in the security database. If you
|
||||
want to use a file from the current directory, please precede it with "./"
|
||||
prefix, in order to avoid confusion with a nickname.
|
||||
With Secure Transport, this can also be the nickname of the certificate you
|
||||
wish to authenticate with as it is named in the security database. If you want
|
||||
to use a file from the current directory, please precede it with "./" prefix,
|
||||
in order to avoid confusion with a nickname.
|
||||
|
||||
When using a client certificate, you most likely also need to provide a
|
||||
private key with \fICURLOPT_PROXY_SSLKEY(3)\fP.
|
||||
|
|
|
|||
|
|
@ -43,11 +43,6 @@ For OpenSSL and GnuTLS valid examples of cipher lists include \fBRC4-SHA\fP,
|
|||
\fBSHA1+DES\fP, \fBTLSv1\fP and \fBDEFAULT\fP. The default list is normally
|
||||
set when you compile OpenSSL.
|
||||
|
||||
For NSS, valid examples of cipher lists include \fBrsa_rc4_128_md5\fP,
|
||||
\fBrsa_aes_128_sha\fP, etc. With NSS you do not add/remove ciphers. If one uses
|
||||
this option then all known ciphers are disabled and only those passed in are
|
||||
enabled.
|
||||
|
||||
For WolfSSL, valid examples of cipher lists include \fBECDHE-RSA-RC4-SHA\fP,
|
||||
\fBAES256-SHA:AES256-SHA256\fP, etc.
|
||||
|
||||
|
|
|
|||
|
|
@ -37,12 +37,12 @@ Pass a long with a bitmask to tell libcurl about specific SSL
|
|||
behaviors. Available bits:
|
||||
.IP CURLSSLOPT_ALLOW_BEAST
|
||||
Tells libcurl to not attempt to use any workarounds for a security flaw in the
|
||||
SSL3 and TLS1.0 protocols. If this option is not used or this bit is set to 0,
|
||||
the SSL layer libcurl uses may use a work-around for this flaw although it
|
||||
might cause interoperability problems with some (older) SSL
|
||||
implementations. WARNING: avoiding this work-around lessens the security, and
|
||||
by setting this option to 1 you ask for exactly that. This option is only
|
||||
supported for Secure Transport, NSS and OpenSSL.
|
||||
SSL3 and TLS1.0 protocols. If this option is not used or this bit is set to
|
||||
0, the SSL layer libcurl uses may use a work-around for this flaw although it
|
||||
might cause interoperability problems with some (older) SSL implementations.
|
||||
WARNING: avoiding this work-around lessens the security, and by setting this
|
||||
option to 1 you ask for exactly that. This option is only supported for
|
||||
Secure Transport and OpenSSL.
|
||||
.IP CURLSSLOPT_NO_REVOKE
|
||||
Tells libcurl to disable certificate revocation checks for those SSL backends
|
||||
where such behavior is present. This option is only supported for Schannel
|
||||
|
|
|
|||
|
|
@ -61,10 +61,7 @@ When the \fIverify\fP value is 0L, the connection succeeds regardless of the
|
|||
names used in the certificate. Use that ability with caution!
|
||||
|
||||
See also \fICURLOPT_PROXY_SSL_VERIFYPEER(3)\fP to verify the digital signature
|
||||
of the proxy certificate. If libcurl is built against NSS and
|
||||
\fICURLOPT_PROXY_SSL_VERIFYPEER(3)\fP is zero,
|
||||
\fICURLOPT_PROXY_SSL_VERIFYHOST(3)\fP is also set to zero and cannot be
|
||||
overridden.
|
||||
of the proxy certificate.
|
||||
.SH DEFAULT
|
||||
2
|
||||
.SH PROTOCOLS
|
||||
|
|
|
|||
|
|
@ -37,10 +37,10 @@ the file name of your client certificate. The default format is "P12" on
|
|||
Secure Transport and "PEM" on other engines, and can be changed with
|
||||
\fICURLOPT_SSLCERTTYPE(3)\fP.
|
||||
|
||||
With NSS or Secure Transport, this can also be the nickname of the certificate
|
||||
you wish to authenticate with as it is named in the security database. If you
|
||||
want to use a file from the current directory, please precede it with "./"
|
||||
prefix, in order to avoid confusion with a nickname.
|
||||
With Secure Transport, this can also be the nickname of the certificate you
|
||||
wish to authenticate with as it is named in the security database. If you want
|
||||
to use a file from the current directory, please precede it with "./" prefix,
|
||||
in order to avoid confusion with a nickname.
|
||||
|
||||
(Schannel only) Client certificates can be specified by a path expression to a
|
||||
certificate store. (You can import \fIPFX\fP to a store first). You can use
|
||||
|
|
|
|||
|
|
@ -42,11 +42,6 @@ For OpenSSL and GnuTLS valid examples of cipher lists include \fBRC4-SHA\fP,
|
|||
\fBSHA1+DES\fP, \fBTLSv1\fP and \fBDEFAULT\fP. The default list is normally
|
||||
set when you compile OpenSSL.
|
||||
|
||||
For NSS, valid examples of cipher lists include \fBrsa_rc4_128_md5\fP,
|
||||
\fBrsa_aes_128_sha\fP, etc. With NSS you do not add/remove ciphers. If one uses
|
||||
this option then all known ciphers are disabled and only those passed in are
|
||||
enabled.
|
||||
|
||||
For WolfSSL, valid examples of cipher lists include \fBECDHE-RSA-RC4-SHA\fP,
|
||||
\fBAES256-SHA:AES256-SHA256\fP, etc.
|
||||
|
||||
|
|
|
|||
|
|
@ -52,8 +52,8 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
Added in 7.42.0. This option is currently only supported by the NSS and
|
||||
Secure Transport (on iOS 7.0 or later, or OS X 10.9 or later) TLS backends.
|
||||
Added in 7.42.0. This option is currently only supported by the Secure
|
||||
Transport (on iOS 7.0 or later, or OS X 10.9 or later) TLS backend.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if false start is supported by the SSL backend, otherwise
|
||||
returns CURLE_NOT_BUILT_IN.
|
||||
|
|
|
|||
|
|
@ -40,8 +40,8 @@ SSL3 and TLS1.0 protocols. If this option is not used or this bit is set to 0,
|
|||
the SSL layer libcurl uses may use a work-around for this flaw although it
|
||||
might cause interoperability problems with some (older) SSL
|
||||
implementations. WARNING: avoiding this work-around lessens the security, and
|
||||
by setting this option to 1 you ask for exactly that. This option is only
|
||||
supported for Secure Transport, NSS and OpenSSL.
|
||||
by setting this option to 1 you ask for exactly that. This option is only
|
||||
supported for Secure Transport and OpenSSL.
|
||||
.IP CURLSSLOPT_NO_REVOKE
|
||||
Tells libcurl to disable certificate revocation checks for those SSL backends
|
||||
where such behavior is present. This option is only supported for Schannel
|
||||
|
|
|
|||
|
|
@ -55,8 +55,8 @@ if(curl) {
|
|||
}
|
||||
.fi
|
||||
.SH AVAILABILITY
|
||||
Added in 7.41.0. This option is currently only supported by the OpenSSL, GnuTLS
|
||||
and NSS TLS backends.
|
||||
Added in 7.41.0. This option is currently only supported by the OpenSSL and
|
||||
GnuTLS TLS backends.
|
||||
.SH RETURN VALUE
|
||||
Returns CURLE_OK if OCSP stapling is supported by the SSL backend, otherwise
|
||||
returns CURLE_NOT_BUILT_IN.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue