SSL context options
  SSL context options — SSL context option listing
  
 
  Descrizione
  
   Context options for ssl:// and tls://
   transports.
  
  
 
  Opzioni
  
   
    
     - 
      peer_namestring
- 
      
       Peer name to be used. If this value is not set, then the name is guessed
       based on the hostname used when opening the stream.
       
- 
      verify_peerbool
- 
      
       Require verification of SSL certificate used.
       
       Defaults to true.
 
- 
      verify_peer_namebool
- 
      
       Require verification of peer name.
       
       Defaults to true.
 
- 
      allow_self_signedbool
- 
      
       Allow self-signed certificates. Requires
       verify_peer.
 
       Defaults to false
 
- 
      cafilestring
- 
      
       Location of Certificate Authority file on local filesystem
       which should be used with the verify_peercontext option to authenticate the identity of the remote peer.
 
- 
      capathstring
- 
      
       If cafileis not specified or if the certificate
       is not found there, the directory pointed to bycapathis searched for a suitable certificate.capathmust be a correctly hashed certificate directory.
 
- 
      local_certstring
- 
      
       Path to local certificate file on filesystem.  It must be a
       PEM encoded file which contains your certificate and
       private key. It can optionally contain the certificate chain of issuers.
       The private key also may be contained in a separate file specified
       by local_pk.
 
- 
      local_pkstring
- 
      
       Path to local private key file on filesystem in case of separate
       files for certificate (local_cert) and private key.
 
- 
      passphrasestring
- 
      
       Passphrase with which your local_certfile
       was encoded.
 
- 
      verify_depthint
- 
      
       Abort if the certificate chain is too deep.
       
       Defaults to no verification.
       
- 
      ciphersstring
- 
      
       Sets the list of available ciphers. The format of the string is described
       in » ciphers(1).
       
       Defaults to DEFAULT.
 
- 
      capture_peer_certbool
- 
      
       If set to trueapeer_certificatecontext option
       will be created containing the peer certificate.
 
- 
      capture_peer_cert_chainbool
- 
      
       If set to trueapeer_certificate_chaincontext
       option will be created containing the certificate chain.
 
- 
      SNI_enabledbool
- 
      
       If set to trueserver name indication will be enabled. Enabling SNI
       allows multiple certificates on the same IP address.
 
- 
      disable_compressionbool
- 
      
       If set, disable TLS compression. This can help mitigate the CRIME attack
       vector.
       
- 
      peer_fingerprintstring | array
- 
      
       Aborts when the remote certificate digest doesn't match the specified
       hash.
       
       When a string is used, the length will determine which hashing algorithm
       is applied, either "md5" (32) or "sha1" (40).
       
       When an array is used, the keys indicate the hashing algorithm name
       and each corresponding value is the expected digest.
       
- 
      security_levelint
- 
      
       Sets the security level. If not specified the library default security level is used.
       The security levels are described in
       » SSL_CTX_get_security_level(3).
       
       Available as of PHP 7.2.0 and OpenSSL 1.1.0.
       
 
 
 
  Note
  Nota: 
   
    Because ssl:// is the underlying transport for the
    https:// and
    ftps:// wrappers,
    any context options which apply to ssl:// also apply to
    https:// and ftps://.
   
  
  Nota: 
   
    For SNI (Server Name Indication) to be available, then PHP must be compiled
    with OpenSSL 0.9.8j or greater. Use the
    OPENSSL_TLSEXT_SERVER_NAME to determine whether SNI is
    supported.