curl: support embedding a CA bundle

Add the ability to embed a CA bundle into the curl binary. It is used
when no other runtime or build-time option set one.

This helps curl-for-win macOS and Linux builds to run standalone, and
also helps Windows builds to avoid picking up the CA bundle from an
arbitrary (possibly world-writable) location (though this behaviour is
not currently disablable).

Usage:
- cmake: `-DCURL_CA_EMBED=/path/to/curl-ca-bundle.crt`
- autotools: `--with-ca-embed=/path/to/curl-ca-bundle.crt`
- Makefile.mk: `CURL_CA_EMBED=/path/to/curl-ca-bundle.crt`

Also add new command-line option `--dump-ca-embed` to dump the embedded
CA bundle to standard output.

Closes #14059
This commit is contained in:
Viktor Szakats 2024-06-29 03:30:14 +02:00
parent 87aa4ebd82
commit 8a3740bc8e
No known key found for this signature in database
GPG key ID: B5ABD165E2AEF201
26 changed files with 268 additions and 14 deletions

View file

@ -89,6 +89,7 @@ DPAGES = \
doh-cert-status.md \
doh-insecure.md \
doh-url.md \
dump-ca-embed.md \
dump-header.md \
ech.md \
egd-file.md \

View file

@ -10,6 +10,7 @@ Multi: boolean
See-also:
- cacert
- capath
- dump-ca-embed
- insecure
Example:
- --ca-native $URL

View file

@ -10,6 +10,7 @@ Added: 7.5
Multi: single
See-also:
- capath
- dump-ca-embed
- insecure
Example:
- --cacert CA-file.txt $URL

View file

@ -10,6 +10,7 @@ Added: 7.9.8
Multi: single
See-also:
- cacert
- dump-ca-embed
- insecure
Example:
- --capath /local/directory $URL

View file

@ -0,0 +1,25 @@
---
c: Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
SPDX-License-Identifier: curl
Long: dump-ca-embed
Help: Write the embedded CA bundle to standard output
Protocols: TLS
Category: http proxy tls
Added: 8.10.0
Multi: single
See-also:
- ca-native
- cacert
- capath
- proxy-ca-native
- proxy-cacert
- proxy-capath
Example:
- --dump-ca-embed
---
# `--dump-ca-embed`
Write the CA bundle embedded in curl to standard output, then quit.
If curl was not built with a default CA bundle embedded, the output is empty.

View file

@ -10,6 +10,7 @@ Multi: boolean
See-also:
- cacert
- capath
- dump-ca-embed
- insecure
Example:
- --proxy-ca-native $URL

View file

@ -11,6 +11,7 @@ See-also:
- proxy-capath
- cacert
- capath
- dump-ca-embed
- proxy
Example:
- --proxy-cacert CA-file.txt -x https://proxy $URL

View file

@ -11,6 +11,7 @@ See-also:
- proxy-cacert
- proxy
- capath
- dump-ca-embed
Example:
- --proxy-capath /local/directory -x https://proxy $URL
---

View file

@ -54,6 +54,7 @@
--doh-cert-status 7.76.0
--doh-insecure 7.76.0
--doh-url 7.62.0
--dump-ca-embed 8.10.0
--dump-header (-D) 5.7
--ech 8.8.0
--egd-file 7.7