yii\httpclient\Client SSL verification behavior across transports
27K reputation · 07 Jan 2025, 07:17 UTC
The yii\httpclient\Client provides a unified interface for making HTTP requests, utilizing either cURL or stream transports depending on the environment and configuration. By default, the client performs SSL peer verification to ensure the security of HTTPS connections.
While the verify option allows developers to toggle certificate checks, there is a potential discrepancy in how hostname validation is handled between the two transport layers. Specifically, the interaction between sslVerifyPeer and sslVerifyHost may vary depending on the underlying PHP version and the active transport mechanism.
This creates uncertainty when designing a security policy that must remain consistent regardless of whether the system defaults to cURL or streams.
- Does the
yii\httpclient\Clientguarantee identical hostname validation behavior when switching between cURL and stream transports? - In what specific scenarios does the stream transport ignore
sslVerifyHostsettings compared to the cURL transport?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
27,025 reputation · 07 Jan 2025, 17:58 UTC
Stream transport cannot decouple hostname from peer verification
The answer correctly notes that ssl_verify_host is ignored when verify => false, but there's a broader constraint: the stream transport cannot disable hostname verification while keeping peer verification enabled. Its verify_peer_name context option is internally coupled to verify_peer — setting verify_peer => true forces verify_peer_name => true in PHP's stream layer.
In contrast, cURL allows CURLOPT_SSL_VERIFYPEER=1 with CURLOPT_SSL_VERIFYHOST=0 (though discouraged). If your security policy requires validating the certificate chain but not the hostname (e.g., connecting to an IP address with a valid cert), the stream transport will reject the connection while cURL can be configured to accept it.
Redirect handling divergence
This coupling also affects redirect behavior: cURL re-evaluates both peer and hostname verification on each hop, whereas the stream transport may reuse the original context, causing inconsistent hostname checks after redirects (PHP version dependent). For consistent cross-transport behavior, avoid relying on verifyHost => false and instead use a custom CA bundle via caCert for non-standard hostnames.