From b8c302dcbae53a79a85b42b9acfabd392a8a530e Mon Sep 17 00:00:00 2001 From: Patrick Schlangen Date: Sun, 30 Oct 2022 22:04:20 +0100 Subject: [PATCH] docs: remove performance note in CURLOPT_SSL_VERIFYPEER This note became obsolete since PR #7892 (see also discussion in the PR comments). Closes #9832 --- docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 | 9 --------- 1 file changed, 9 deletions(-) diff --git a/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 b/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 index 1a0c1b5a86..7b643a2078 100644 --- a/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 +++ b/docs/libcurl/opts/CURLOPT_SSL_VERIFYPEER.3 @@ -61,15 +61,6 @@ man-in-the-middle the communication without you knowing it. Disabling verification makes the communication insecure. Just having encryption on a transfer is not enough as you cannot be sure that you are communicating with the correct end-point. - -NOTE: even when this option is disabled, depending on the used TLS backend, -curl may still load the certificate file specified in -\fICURLOPT_CAINFO(3)\fP. curl default settings in some distributions might use -quite a large file as a default setting for \fICURLOPT_CAINFO(3)\fP, so -loading the file can be quite expensive, especially when dealing with many -connections. Thus, in some situations, you might want to disable verification -fully to save resources by setting \fICURLOPT_CAINFO(3)\fP to NULL - but -please also consider the warning above! .SH DEFAULT By default, curl assumes a value of 1. .SH PROTOCOLS -- 2.47.3