diff options
author | Daniel Stenberg <daniel@haxx.se> | 2021-11-25 13:17:49 +0100 |
---|---|---|
committer | Daniel Stenberg <daniel@haxx.se> | 2021-11-25 22:31:15 +0100 |
commit | c50edee022ec955afc73f76a1c9603e4853601cc (patch) | |
tree | b8789af4adff48a7f7b5aad83dfa4100524858b4 | |
parent | 8c0336cf5dfc1bf6afb7e0dbc7877c82cd20de01 (diff) | |
download | curl-c50edee022ec955afc73f76a1c9603e4853601cc.tar.gz |
insecure.d: detail its use for SFTP and SCP as well
Closes #8056
-rw-r--r-- | docs/cmdline-opts/insecure.d | 25 |
1 files changed, 14 insertions, 11 deletions
diff --git a/docs/cmdline-opts/insecure.d b/docs/cmdline-opts/insecure.d index 0fd09cfa2..90c1c0802 100644 --- a/docs/cmdline-opts/insecure.d +++ b/docs/cmdline-opts/insecure.d @@ -1,22 +1,25 @@ Long: insecure Short: k -Help: Allow insecure server connections when using SSL -Protocols: TLS +Help: Allow insecure server connections +Protocols: TLS SFTP SCP See-also: proxy-insecure cacert capath -Category: tls +Category: tls sftp scp Example: --insecure $URL Added: 7.10 --- -By default, every SSL/TLS connection curl makes is verified to be secure -before the transfer takes place. This option makes curl skip the verification -step and proceed without checking. - -When this option is not used, curl verifies the server's TLS certificate -before it continues: that the certificate contains the right name which -matches the host name used in the URL and that the certificate has been signed -by a CA certificate present in the cert store. +By default, every secure connection curl makes is verified to be secure before +the transfer takes place. This option makes curl skip the verification step +and proceed without checking. +When this option is not used for protocols using TLS, curl verifies the +server's TLS certificate before it continues: that the certificate contains +the right name which matches the host name used in the URL and that the +certificate has been signed by a CA certificate present in the cert store. See this online resource for further details: https://curl.se/docs/sslcerts.html +For SFTP and SCP, this option makes curl skip the *known_hosts* verification. +*known_hosts* is a file normally stored in the user's home directory in the +\&.ssh subdirectory, which contains host names and their public keys. + **WARNING**: using this option makes the transfer insecure. |