openssl: enable builds for *both* engines and providers

OpenSSL3 can in fact have both enabled at once. Load the provider and
key/cert appropriately. When loading a provider, the user can now also
set an associated "property string".

Work on this was sponsored by Valantic.

Closes #17165
This commit is contained in:
Daniel Stenberg 2025-04-08 11:45:17 +02:00
parent e0ebc3ff13
commit f2ce6c46b9
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
3 changed files with 151 additions and 83 deletions

View file

@ -17,7 +17,7 @@ Added-in: 7.9.3
# NAME
CURLOPT_SSLENGINE - SSL engine identifier
CURLOPT_SSLENGINE - Set SSL engine or provider
# SYNOPSIS
@ -30,11 +30,16 @@ CURLcode curl_easy_setopt(CURL *handle, CURLOPT_SSLENGINE, char *id);
# DESCRIPTION
Pass a pointer to a null-terminated string as parameter. It is used as the
identifier for the crypto engine you want to use for your private key.
identifier for the *engine* or *provider* you want to use for your private
key. OpenSSL 1 had engines, OpenSSL 3 has providers.
The application does not have to keep the string around after setting this
option.
When asking libcurl to use a provider, the application can also optionally
provide a *property*, a set of name value pairs. Such a property can be
specified separated from the name with a colon (`:`).
Using this option multiple times makes the last set string override the
previous ones. Set it to NULL to disable its use again.