insecure.d: detail its use for SFTP and SCP as well

Closes #8056
This commit is contained in:
Daniel Stenberg 2021-11-25 13:17:49 +01:00
parent 8c0336cf5d
commit c50edee022
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2

View file

@ -1,22 +1,25 @@
Long: insecure
Short: k
Help: Allow insecure server connections when using SSL
Protocols: TLS
Help: Allow insecure server connections
Protocols: TLS SFTP SCP
See-also: proxy-insecure cacert capath
Category: tls
Category: tls sftp scp
Example: --insecure $URL
Added: 7.10
---
By default, every SSL/TLS connection curl makes is verified to be secure
before the transfer takes place. This option makes curl skip the verification
step and proceed without checking.
When this option is not used, curl verifies the server's TLS certificate
before it continues: that the certificate contains the right name which
matches the host name used in the URL and that the certificate has been signed
by a CA certificate present in the cert store.
By default, every secure connection curl makes is verified to be secure before
the transfer takes place. This option makes curl skip the verification step
and proceed without checking.
When this option is not used for protocols using TLS, curl verifies the
server's TLS certificate before it continues: that the certificate contains
the right name which matches the host name used in the URL and that the
certificate has been signed by a CA certificate present in the cert store.
See this online resource for further details:
https://curl.se/docs/sslcerts.html
For SFTP and SCP, this option makes curl skip the *known_hosts* verification.
*known_hosts* is a file normally stored in the user's home directory in the
\&.ssh subdirectory, which contains host names and their public keys.
**WARNING**: using this option makes the transfer insecure.