| .\" ************************************************************************** | 
 | .\" *                                  _   _ ____  _ | 
 | .\" *  Project                     ___| | | |  _ \| | | 
 | .\" *                             / __| | | | |_) | | | 
 | .\" *                            | (__| |_| |  _ <| |___ | 
 | .\" *                             \___|\___/|_| \_\_____| | 
 | .\" * | 
 | .\" * Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al. | 
 | .\" * | 
 | .\" * This software is licensed as described in the file COPYING, which | 
 | .\" * you should have received as part of this distribution. The terms | 
 | .\" * are also available at https://curl.se/docs/copyright.html. | 
 | .\" * | 
 | .\" * You may opt to use, copy, modify, merge, publish, distribute and/or sell | 
 | .\" * copies of the Software, and permit persons to whom the Software is | 
 | .\" * furnished to do so, under the terms of the COPYING file. | 
 | .\" * | 
 | .\" * This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY | 
 | .\" * KIND, either express or implied. | 
 | .\" * | 
 | .\" * SPDX-License-Identifier: curl | 
 | .\" * | 
 | .\" ************************************************************************** | 
 | .\" | 
 | .TH CURLOPT_CAINFO 3 "17 Jun 2014" "libcurl 7.37.0" "curl_easy_setopt options" | 
 | .SH NAME | 
 | CURLOPT_CAINFO \- path to Certificate Authority (CA) bundle | 
 | .SH SYNOPSIS | 
 | .nf | 
 | #include <curl/curl.h> | 
 |  | 
 | CURLcode curl_easy_setopt(CURL *handle, CURLOPT_CAINFO, char *path); | 
 | .fi | 
 | .SH DESCRIPTION | 
 | Pass a char * to a null-terminated string naming a file holding one or more | 
 | certificates to verify the peer with. | 
 |  | 
 | If \fICURLOPT_SSL_VERIFYPEER(3)\fP is zero and you avoid verifying the | 
 | server's certificate, \fICURLOPT_CAINFO(3)\fP need not even indicate an | 
 | accessible file. | 
 |  | 
 | This option is by default set to the system path where libcurl's CA | 
 | certificate bundle is assumed to be stored, as established at build time. | 
 |  | 
 | If curl is built against the NSS SSL library, the NSS PEM PKCS#11 module | 
 | (libnsspem.so) needs to be available for this option to work properly. | 
 | Starting with curl 7.55.0, if both \fICURLOPT_CAINFO(3)\fP and | 
 | \fICURLOPT_CAPATH(3)\fP are unset, NSS-linked libcurl tries to load | 
 | libnssckbi.so, which contains a more comprehensive set of trust information | 
 | than supported by nss-pem, because libnssckbi.so also includes information | 
 | about distrusted certificates. | 
 |  | 
 | (iOS and macOS) When curl uses Secure Transport this option is supported. If | 
 | the option is not set, then curl will use the certificates in the system and | 
 | user Keychain to verify the peer. | 
 |  | 
 | (Schannel) This option is supported for Schannel in Windows 7 or later but we | 
 | recommend not using it until Windows 8 since it works better starting then. | 
 | If the option is not set, then curl will use the certificates in the Windows' | 
 | store of root certificates (the default for Schannel). | 
 |  | 
 | The application does not have to keep the string around after setting this | 
 | option. | 
 |  | 
 | The default value for this can be figured out with \fICURLINFO_CAINFO(3)\fP. | 
 | .SH DEFAULT | 
 | Built-in system specific. When curl is built with Secure Transport or | 
 | Schannel, this option is not set by default. | 
 | .SH PROTOCOLS | 
 | All TLS based protocols: HTTPS, FTPS, IMAPS, POP3S, SMTPS etc. | 
 | .SH EXAMPLE | 
 | .nf | 
 | CURL *curl = curl_easy_init(); | 
 | if(curl) { | 
 |   curl_easy_setopt(curl, CURLOPT_URL, "https://example.com/"); | 
 |   curl_easy_setopt(curl, CURLOPT_CAINFO, "/etc/certs/cabundle.pem"); | 
 |   ret = curl_easy_perform(curl); | 
 |   curl_easy_cleanup(curl); | 
 | } | 
 | .fi | 
 | .SH AVAILABILITY | 
 | For the SSL engines that do not support certificate files the | 
 | \fICURLOPT_CAINFO(3)\fP option is ignored. Schannel support added in libcurl | 
 | 7.60. | 
 | .SH RETURN VALUE | 
 | Returns CURLE_OK if the option is supported, CURLE_UNKNOWN_OPTION if not, or | 
 | CURLE_OUT_OF_MEMORY if there was insufficient heap space. | 
 | .SH "SEE ALSO" | 
 | .BR CURLOPT_CAINFO_BLOB "(3), " CURLOPT_CAPATH "(3), " | 
 | .BR CURLOPT_SSL_VERIFYPEER "(3), " CURLOPT_SSL_VERIFYHOST "(3), " | 
 | .BR CURLINFO_CAINFO "(3), " CURLOPT_CA_CACHE_TIMEOUT "(3), " |