Go to file
Alex Rousskov 3d90ec5448 proxy: Support HTTPS proxy and SOCKS+HTTP(s)
HTTPS proxies:

An HTTPS proxy receives all transactions over an SSL/TLS connection. Once a
secure connection with the proxy is established, the user agent uses the proxy
as usual, including sending CONNECT requests to instruct the proxy to establish
a [usually secure] TCP tunnel with an origin server. HTTPS proxies protect
nearly all aspects of user-proxy communications as opposed to HTTP proxies that
receive all requests (including CONNECT requests) in vulnerable clear text.

With HTTPS proxies, it is possible to have two concurrent _nested_ SSL/TLS
sessions: the "outer" one between the user agent and the proxy and the "inner"
one between the user agent and the origin server (through the proxy). This
change adds supports for such nested sessions as well.

The secure connection with the proxy requires its own set of the usual
SSL/TLS-related options (their descriptions need polishing):

  --proxy-cacert FILE        CA certificate to verify peer against
  --proxy-capath DIR         CA directory to verify peer against
  --proxy-cert CERT[:PASSWD] Client certificate file and password
  --proxy-cert-type TYPE     Certificate file type (DER/PEM/ENG)
  --proxy-ciphers LIST       SSL ciphers to use
  --proxy-crlfile FILE       Get a CRL list in PEM format from the given file
  --proxy-insecure           Allow connections to SSL sites without certs
  --proxy-key KEY            Private key file name
  --proxy-key-type TYPE      Private key file type (DER/PEM/ENG)
  --proxy-pass PASS          Pass phrase for the private key
  --proxy-ssl-allow-beast    Allow security flaw to improve interop
  --proxy-sslv2              Use SSLv2
  --proxy-sslv3              Use SSLv3
  --proxy-tlsv1              Use TLSv1
  --proxy-tlsuser USER       TLS username
  --proxy-tlspassword STRING TLS password
  --proxy-tlsauthtype STRING TLS authentication type (default SRP)

All --proxy-foo options are independent from their --foo counterparts, except
--proxy-crlfile defaults to --crlfile and --proxy-capath defaults to --capath.

Curl now also supports %{proxy_ssl_verify_result} --write-out variable,
similar to the existing %{ssl_verify_result} variable.

SOCKS proxy + HTTP/HTTPS proxy combination:

If both --socks* and --proxy options are given, Curl first connects to the
SOCKS proxy and then connects (through SOCKS) to the HTTP or HTTPS proxy.
2015-06-24 23:59:18 +02:00
CMake CMake: fix winsock2 detection on windows 2015-02-19 20:11:04 +01:00
docs proxy: Support HTTPS proxy and SOCKS+HTTP(s) 2015-06-24 23:59:18 +02:00
include proxy: Support HTTPS proxy and SOCKS+HTTP(s) 2015-06-24 23:59:18 +02:00
lib proxy: Support HTTPS proxy and SOCKS+HTTP(s) 2015-06-24 23:59:18 +02:00
m4 build: Fix typo from OpenSSL 1.0.2 version detection fix 2015-06-14 16:01:18 -04:00
packages proxy: Support HTTPS proxy and SOCKS+HTTP(s) 2015-06-24 23:59:18 +02:00
projects INSTALL: Advise use of non-native SSL for Windows <= XP 2015-06-20 18:45:25 -04:00
scripts scripts: moved contributors.sh and contrithanks.sh into subdir 2015-05-27 16:10:08 +02:00
src proxy: Support HTTPS proxy and SOCKS+HTTP(s) 2015-06-24 23:59:18 +02:00
tests test1531: verify POSTFIELDSIZE set after add_handle 2015-06-23 17:51:03 -07:00
winbuild INSTALL: Advise use of non-native SSL for Windows <= XP 2015-06-20 18:45:25 -04:00
.gitattributes Tell git to not convert configure-related files. 2012-07-17 20:35:23 +02:00
.gitignore gitignore: Ignore Windows build output directories 2015-04-16 18:24:42 -04:00
.travis.yml .travis.yml: Change CI make test to make test-full 2015-03-10 20:37:17 +01:00
acinclude.m4 configure: remove missing and make it autogenerate 2015-04-30 18:40:35 +02:00
buildconf configure: remove missing and make it autogenerate 2015-04-30 18:40:35 +02:00
buildconf.bat curl tool: renaming hugehelp files to tool_hugehelp 2012-12-26 23:30:54 +01:00
CHANGES CHANGES: move all contents from CHANGES to CHANGES.0 2010-06-21 22:27:39 +02:00
CHANGES.0 code/docs: Use correct case for IPv4 and IPv6 2014-12-27 11:31:55 +00:00
CMakeLists.txt openssl: remove all uses of USE_SSLEAY 2015-03-05 10:57:52 +01:00
configure.ac Require nghttp2 v1.0.0 2015-05-18 09:33:48 +02:00
CONTRIBUTING.md CONTRIBUTING.md: remove the sourceforge mention 2015-04-30 18:35:43 +02:00
COPYING COPYING: Bumped copyright year to 2015 2015-01-01 05:14:38 +00:00
CTestConfig.cmake ENH: move dashboard location 2009-07-15 19:40:46 +00:00
curl-config.in curl-config.in: eliminate double quotes around CURL_CA_BUNDLE 2015-02-25 10:23:07 +01:00
GIT-INFO curl tool: renaming hugehelp files to tool_hugehelp 2012-12-26 23:30:54 +01:00
libcurl.pc.in build: prevent global LIBS from influencing src and lib build targets 2012-12-03 22:41:18 +01:00
MacOSX-Framework MacOSX-Framework: use @rpath instead of @executable_path 2015-03-09 23:39:27 +01:00
Makefile.am scripts: add zsh.pl for generating zsh completion 2015-05-24 00:03:14 +02:00
Makefile.dist VC build: added sspi define for winssl-zlib builds. 2014-12-09 13:30:28 +01:00
maketgz log2changes.pl: moved to scripts/ 2015-05-24 00:09:23 +02:00
README README: use secure protocol for Git repository 2015-06-15 23:45:34 +02:00
RELEASE-NOTES bump: start the journey toward 7.44.0 2015-06-17 13:59:33 +02:00

                                  _   _ ____  _
                              ___| | | |  _ \| |
                             / __| | | | |_) | |
                            | (__| |_| |  _ <| |___
                             \___|\___/|_| \_\_____|

README

  Curl is a command line tool for transferring data specified with URL
  syntax. Find out how to use curl by reading the curl.1 man page or the
  MANUAL document. Find out how to install Curl by reading the INSTALL
  document.

  libcurl is the library curl is using to do its job. It is readily
  available to be used by your software. Read the libcurl.3 man page to
  learn how!

  You find answers to the most frequent questions we get in the FAQ document.

  Study the COPYING file for distribution terms and similar. If you distribute
  curl binaries or other binaries that involve libcurl, you might enjoy the
  LICENSE-MIXING document.

CONTACT

  If you have problems, questions, ideas or suggestions, please contact us
  by posting to a suitable mailing list. See http://curl.haxx.se/mail/

  All contributors to the project are listed in the THANKS document.

WEB SITE

  Visit the curl web site for the latest news and downloads:

        http://curl.haxx.se/

GIT

  To download the very latest source off the GIT server do this:

    git clone https://github.com/bagder/curl.git

  (you'll get a directory named curl created, filled with the source code)

NOTICE

  Curl contains pieces of source code that is Copyright (c) 1998, 1999
  Kungliga Tekniska Högskolan. This notice is included here to comply with the
  distribution terms.