diff options
Diffstat (limited to 'docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3')
| -rw-r--r-- | docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 | 14 |
1 files changed, 12 insertions, 2 deletions
diff --git a/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 b/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 index 1247f3fd..bd31956d 100644 --- a/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 +++ b/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 @@ -5,7 +5,7 @@ .\" * | (__| |_| | _ <| |___ .\" * \___|\___/|_| \_\_____| .\" * -.\" * Copyright (C) 1998 - 2017, Daniel Stenberg, <daniel@haxx.se>, et al. +.\" * Copyright (C) 1998 - 2018, Daniel Stenberg, <daniel@haxx.se>, et al. .\" * .\" * This software is licensed as described in the file COPYING, which .\" * you should have received as part of this distribution. The terms @@ -20,7 +20,7 @@ .\" * .\" ************************************************************************** .\" -.TH CURLOPT_SSL_VERIFYPEER 3 "February 09, 2017" "libcurl 7.60.0" "curl_easy_setopt options" +.TH CURLOPT_SSL_VERIFYPEER 3 "June 24, 2018" "libcurl 7.61.0" "curl_easy_setopt options" .SH NAME CURLOPT_SSL_VERIFYPEER \- verify the peer's SSL certificate @@ -58,6 +58,15 @@ man-in-the-middle the communication without you knowing it. Disabling verification makes the communication insecure. Just having encryption on a transfer is not enough as you cannot be sure that you are communicating with the correct end-point. + +NOTE: even when this option is disabled, depending on the used TLS backend, +curl may still load the certificate file specified in +\fICURLOPT_CAINFO(3)\fP. curl default settings in some distributions might use +quite a large file as a default setting for \fICURLOPT_CAINFO(3)\fP, so +loading the file can be quite expensive, especially when dealing with many +connections. Thus, in some situations, you might want to disable verification +fully to save resources by setting \fICURLOPT_CAINFO(3)\fP to NULL - but +please also consider the warning above! .SH DEFAULT By default, curl assumes a value of 1. .SH PROTOCOLS @@ -82,3 +91,4 @@ Returns CURLE_OK if the option is supported, and CURLE_UNKNOWN_OPTION if not. .BR CURLOPT_SSL_VERIFYHOST "(3), " .BR CURLOPT_PROXY_SSL_VERIFYPEER "(3), " .BR CURLOPT_PROXY_SSL_VERIFYHOST "(3), " +.BR CURLOPT_CAINFO "(3), " |
