Pardon me if I'm missing something, but that sounds like a horrible design decision, and anyone who tries to use TLS streams without reading the documentation is fooled into a false sense of security.
Pardon me if I'm missing something, but that sounds like a horrible design decision, and anyone who tries to use TLS streams without reading the documentation is fooled into a false sense of security.
"We must also specify the expected peer name on the presented certificate with the `CN_match` option, it will not be inferred from the URL and if it is not specified, the name on the certificate will not be validated."
WTF? Who ever got the idea that this is something that can ever hit production?
Effectively if you write any code you're not going to deploy yourself, you have to specify the CN_match and verify_peer. Others will not know about the limitations, so this function is messed up until after 5.5 is EOLed.
Designing APIs is hard and bad defaults can hurt for many major versions after they're changed.
The next article will cover the changes in 5.6 and why you don't need to set those ctx opts any more (and a few more you might want to set instead)
You mean in the version that's not properly released or anywhere close to production ready? 5.5 still defaults to not verifying according to the documentation.