1
0
mirror of https://github.com/moparisthebest/wget synced 2024-07-03 16:38:41 -04:00

[svn] Explain certificate checking in more detail.

This commit is contained in:
hniksic 2005-05-11 01:44:43 -07:00
parent 646a9e10dc
commit 7bde962912
2 changed files with 25 additions and 3 deletions

View File

@ -1,3 +1,8 @@
2005-05-11 Hrvoje Niksic <hniksic@xemacs.org>
* wget.texi (HTTPS (SSL/TLS) Options): Explain certificate
checking in more detail.
2005-05-08 Hrvoje Niksic <hniksic@xemacs.org>
* texi2pod.pl.in: Allow an "EXAMPLES" section.

View File

@ -1369,9 +1369,26 @@ quite rare.
@cindex SSL certificate, check
@item --no-check-certificate
Don't check the server certificate against the available client
authorities. If this is not specified, Wget will break the SSL
handshake if the server certificate is not valid.
Don't check the server certificate against the available certificate
authorities. Also don't require the URL host name to match the common
name presented by the certificate.
As of Wget 1.10, the default is to verify the server's certificate
against the recognized certificate authorities, breaking the SSL
handshake and aborting the download if the verification fails.
Although this provides more secure downloads, it does break
interoperability with some sites that worked with previous Wget
versions, particularly those using self-signed, expired, or otherwise
invalid certificates. This option forces an ``insecure'' mode of
operation that turns the certificate verification errors into warnings
and allows you to proceed.
If you see errors involving ``certificate verify failed'' or ``common
name doesn't match requested host name'', you need to use this option
to proceed with the download. @emph{Only use this option if you are
otherwise convinced of the site's authenticity, or if you don't care
about the certificate validity.} It is almost always a bad idea to
use this option when transmitting confidential or important data.
@cindex SSL certificate
@item --certificate=@var{file}