Re: Re: Re: PHP Crypt functions - security audit

From: Date: Fri, 20 Sep 2013 00:48:26 +0000
Subject: Re: Re: Re: PHP Crypt functions - security audit
References: 1 2 3 4 5 6 7 8 9 10 11  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
On 19 September 2013 17:41, Pierre Joye <[email protected]> wrote:
> It does when you use curl's win32 SSL support. That makes my previous
> point wrong as we do not compile it with this option but openssl (for
> cross platform compatibility reasons). But as the curl's ca file works
> just fine, everything is good.
>
> Would it make sense to share that option for openssl itself?

I think so, particularly if we did make peer validation the default.
Most Windows users would be happy to just use the system certificate
store, I would think, so that would be one less thing to configure
post-install.

Adam


Thread (25 messages)

« previous php.internals (#69241) next »