A working build of curl 7.88.1 (February 2023) for SCO OpenServer 5.0.7, with full TLS support via statically-linked OpenSSL 1.0.2q.
$ curl -sI https://www.google.com/
HTTP/1.1 200 OK
Content-Type: text/html; charset=ISO-8859-1
...
$ curl https://api.github.com/zen
Encourage flow.
Just want HTTPS on your SCO box? Skip to Install.
curl 8.0 (March 2023) dropped support for 32-bit curl_off_t. SCO 5.0.7
is 32-bit i386 with 32-bit off_t, no off64_t, no large-file support.
7.88.1 is the final release that still supports systems like SCO
(via the --with-n64-deprecated configure opt-in).
Two ways, both ending with curl at /usr/local/bin/curl. Either way you have
to get files onto the box first, by scp, ftp, CD or floppy.
vols/ holds a VOLs distribution, the format OpenServer's own
custom(ADM) and Software Manager install, and the same format the operating
system itself ships on. Copy the three VOL.000.* files to the SCO box, into
any directory, then:
/etc/custom -i -z /tmp/curl-vols -p Tachytelic:CURLRunning /etc/custom with no arguments opens the Software Manager instead,
where Software -> Install New -> From: this host -> Media: Media Images
reaches the same distribution.
It installs to /opt/K/Tachytelic/CURL/7.88.1/ and makes the two files public
as /usr/local/bin/curl and /usr/local/etc/ssl/cert.pem, which is the same
layout the manual method below produces by hand.
Because it is registered software, you also get:
/etc/custom -p Tachytelic:CURL -l # every file it owns
/etc/custom -p Tachytelic:CURL -v strict # verify mode, owner, size, checksum
/etc/custom -p Tachytelic:CURL -r # remove it, symlinks includedcustom lives at /etc/custom and is not on the default PATH in a
non-login shell, so use the full path in scripts.
The binary is 2.1 MB (statically-linked libcurl + OpenSSL, no runtime
deps beyond libc), still small enough to commit. Grab prebuilt/curl,
extras/cacert.pem, copy them to your SCO box:
# scp curl + cacert.pem to the SCO machine, then on SCO:
chmod +x curl
mv curl /usr/local/bin/curl
# Install the Mozilla CA bundle for HTTPS verification:
mkdir -p /usr/local/etc/ssl
cp cacert.pem /usr/local/etc/ssl/cert.pem
/usr/local/bin/curl --version
/usr/local/bin/curl -sI https://www.google.com/The CA bundle path /usr/local/etc/ssl/cert.pem is baked into the
curl binary as the default, so no --cacert flag is needed.
OpenServer ships its own curl, 7.15.x from the SCO:gwxlibs component, at
/usr/bin/curl. The stock PATH is:
/usr/bin:/bin:/usr/sbin:/sbin:/usr/local/bin
/usr/local/bin is last, so after installing this, plain curl still runs
the stock 7.15.x. That is deliberate: nothing here displaces a tool the
operating system provides. Reach this one by absolute path:
/usr/local/bin/curl --versionor put /usr/local/bin earlier in your PATH if you would rather it won. If
you see error setting certificate verify locations with a CAfile of
/usr/share/curl/curl-ca-bundle.crt, you have reached the stock 7.15.x, not
this build.
On OpenServer 5 Definitive 2018 there is a third one. Xinuos install
curl 7.58.0 during initial system load, self-contained under
/opt/xinuos/bin/curl. It adds nothing to PATH and touches no standard
directory, so it does not collide with either of the above, but it is worth
knowing about: unlike the 7.15.x it does TLS 1.2, so check whether it already
covers what you need before installing this build.
curl is the only thing you need to transfer onto a fresh SCO box. Once it is in place you can fetch everything else over HTTPS from GitHub releases. The full chain on a freshly-installed SCO 5.0.7 (no Skunkware, no extras):
# After curl is installed (above), get GNU tar so you can extract
# .tar.gz releases in one step instead of piping gunzip into tar.
# This first one uses stock SCO tools (gunzip + /usr/bin/tar):
curl -LO https://github.com/tachytelic/Tar-1.34-for-SCO-OpenServer-5/releases/download/v1.0.0/tar-1.34-sco.tar.gz
gunzip -c tar-1.34-sco.tar.gz | /usr/bin/tar xf -
mv install /usr/local/tar-1.34
ln -s /usr/local/tar-1.34/bin/tar /usr/local/bin/gtar
# Strongly recommended next: GNU bash 3.2.57. SCO's /bin/sh is /bin/ksh,
# which is ~20x slower than bash on autoconf-generated configure scripts
# (literally minutes vs seconds). Anything you ever build from source
# benefits, and this is the only build you need before you can run any
# other configure script comfortably:
curl -LO https://github.com/tachytelic/Bash-3.2.57-for-SCO-OpenServer-5/releases/download/v1.0.0/bash-3.2.57-sco.tar.gz
gtar xzf bash-3.2.57-sco.tar.gz
mv install /usr/local/bash-3.2.57
ln -s /usr/local/bash-3.2.57/bin/bash /usr/local/bin/bash
# After that, pick whichever of the rest you need:
# Python 3.6.15 with HTTPS + sqlite3 (~35 MB)
curl -LO https://github.com/tachytelic/Python-3.6.15-for-SCO-OpenServer-5/releases/download/v1.0.1/python-3.6.15-sco.tar.gz
gtar xzf python-3.6.15-sco.tar.gz
mv install /usr/local/python-3.6.15
ln -s /usr/local/python-3.6.15/bin/python3 /usr/local/bin/python3
# Lua 5.4.7 (single binary, no tarball)
curl -LO https://github.com/tachytelic/Lua-5.4.7-for-SCO-OpenServer-5/releases/download/v1.0.0/lua
chmod +x lua && mv lua /usr/local/bin/lua
# rsync 3.2.7 (single binary)
curl -LO https://github.com/tachytelic/rsync-3.2.7-for-SCO-OpenServer-5/releases/download/v1.0.0/rsync
chmod +x rsync && mv rsync /usr/local/bin/rsync
# nano 2.9.8 (full-screen editor with syntax highlighting + 256-colour terminfo)
curl -LO https://github.com/tachytelic/Nano-2.9.8-for-SCO-OpenServer-5/releases/download/v1.0.0/nano-2.9.8-sco.tar.gz
gtar xzf nano-2.9.8-sco.tar.gz
mv install /usr/local/nano-2.9.8
ln -s /usr/local/nano-2.9.8/bin/nano /usr/local/bin/nano
# coreutils 8.32 (gls/gcp/gdu/gsort/etc. with --color, -h, long options)
curl -LO https://github.com/tachytelic/Coreutils-8.32-for-SCO-OpenServer-5/releases/download/v1.0.0/coreutils-8.32-sco.tar.gz
gtar xzf coreutils-8.32-sco.tar.gz
mv install /usr/local/coreutils-8.32
# a2ps 4.14 (text/source -> PostScript pretty-printer; print to a network
# printer's port 9100 with bash's /dev/tcp). MUST live at /usr/local/a2ps-4.14.
curl -LO https://github.com/tachytelic/a2ps-4.14-for-SCO-OpenServer-5/releases/download/v1.0.0/a2ps-4.14-sco.tar.gz
gtar xzf a2ps-4.14-sco.tar.gz
mv install /usr/local/a2ps-4.14
ln -s /usr/local/a2ps-4.14/bin/a2ps /usr/local/bin/a2ps
# Ghostscript 9.06 (PostScript/PDF interpreter; reads modern PDFs, rasterizes
# for printing). Single self-contained binary - no support files needed.
curl -LO https://github.com/tachytelic/Ghostscript-9.06-for-SCO-OpenServer-5/releases/download/v1.0.0/gs
chmod +x gs && mv gs /usr/local/bin/gs
# jq 1.7.1 (command-line JSON processor with regex; pipe curl's JSON into it).
# Single self-contained binary.
curl -LO https://github.com/tachytelic/jq-1.7.1-for-SCO-OpenServer-5/releases/download/v1.0.0/jq
chmod +x jq && mv jq /usr/local/bin/jq
# ...etc per each repo's READMEThat's the entire bootstrap. Every release verified end-to-end on a SCO
5.0.7 box: HTTPS fetch from github.com works on our curl, the .tar.gz
releases extract cleanly with stock tools, and gtar then handles every
later untar in one shot.
The full hub of available builds is at tachytelic.net/2017/07/sco-openserver-5-binaries/.
- Modern TLS — TLS 1.0/1.1/1.2 (no 1.3 — that needs OpenSSL 1.1.1+, which SCO can't currently build)
- Modern ciphers including ECDHE-RSA-AES256-GCM-SHA384
- Mozilla CA bundle for verifying server certs against real-world certificate authorities
- Protocols:
http,https,ftp,ftps,file - Features: HSTS, alt-svc, NTLM, SSL, TLS-SRP
Compile-time disabled — these need libraries SCO doesn't have, or features that don't fit SCO's runtime:
HTTP/2,HTTP/3(need nghttp2 / ngtcp2)SSH/SCP/SFTPprotocols (need libssh/libssh2)MQTT,RTSP,LDAP,LDAPS,DICT,TELNET,TFTP,POP3/IMAP/SMB/SMTP/GOPHER— none of these are common needs- IPv6 (SCO is IPv4-only)
- IDN, PSL, brotli, zstd, zlib (optional features that need extra libs)
- Threaded resolver (no pthreads on SCO — uses synchronous
gethostbynameinstead, which works fine for normal use)
What's left covers ~99% of what people actually use curl for: HTTP and HTTPS to internet servers.
Absolute paths here, because plain curl reaches OpenServer's stock 7.15.x.
See Which curl am I running? above.
# HEAD request
/usr/local/bin/curl -sI https://example.com/
# Fetch JSON from an HTTPS API
/usr/local/bin/curl -s https://api.github.com/repos/curl/curl | head
# Save to a file
/usr/local/bin/curl -o page.html https://www.google.com/
# Verbose TLS handshake (debug)
/usr/local/bin/curl -v https://example.com/ 2>&1 | grep -E "TLS|SSL|cipher"Mozilla's CA bundle changes occasionally as CAs are added or removed.
The extras/cacert.pem in this repo was the current version at build
time. To refresh:
# On any internet-connected machine:
curl -sLO https://curl.se/ca/cacert.pem
scp cacert.pem root@your-sco-host:/usr/local/etc/ssl/cert.pemIf you installed the native package, /usr/local/etc/ssl/cert.pem is a
symlink into /opt/K, so that overwrites a file the package owns and
custom -p Tachytelic:CURL -v strict will then report a changed size and
checksum for it. That is the check doing its job. Either accept the report,
or keep the replacement bundle somewhere of your own and point at it with
--cacert.
You probably don't need to do this — prebuilt/curl is what build.sh
produces. If you want to rebuild (different version, different config
flags), run build.sh on the SCO box.
This is a native build, not a cross-build.
- GCC 3.4 or later somewhere on the SCO box (the SCO-shipped GCC
2.95.3 is C89-only — curl 7.88 needs C99). The build script refuses to
start with 2.x. If your modern gcc is on PATH as
gcc, just run./build.sh. Otherwise:GCC=/path/to/your/gcc-3.4 ./build.sh. /usr/gnu/bin/{gmake,gtar}- Static OpenSSL 1.0.2 at
/usr/local/lib/{libssl,libcrypto}.awith headers at/usr/local/include/openssl/. SCO's stock 0.9.7 won't do — modern TLS handshakes against current servers need 1.0.2 or 1.1.1+. Build OpenSSL 1.0.2 first:./Configure no-shared no-asm sco5-gcc make depend && make && make install
cd curl-sco
./build.shDownloads curl-7.88.1.tar.gz from curl.se, configures, builds, runs
make install to ./curl_install/, strips. No source patches needed.
That's the nice thing about curl — its configure script has clean
toggles for every optional feature, so the right combination of --with/
--without flags gets us a clean SCO build with no source changes at all.
prebuilt/
curl 2.1 MB stripped binary ← start here
extras/
cacert.pem Mozilla CA bundle (~221 KB)
vols/
VOL.000.000 distribution database ) custom-installable
VOL.000.001 product/component data ) native package,
VOL.000.002 payload, 1.1 MB ) see Install above
build-vols.sh regenerates the three VOL files (run on SCO)
build.sh Native-build script (run on SCO)
curl is © Daniel Stenberg and many contributors, distributed under the curl License. The prebuilt binary is unmodified upstream curl 7.88.1 with no patches applied.
The Mozilla CA bundle (extras/cacert.pem) is provided by Mozilla
Foundation, distributed by curl.se/docs/caextract.html
under the terms described there (MPL 2.0 / public domain hybrid).
The build script in this repo is released under the MIT license — see LICENSE.
If you're keeping a SCO OpenServer 5 box alive, head over to my SCO OpenServer 5 binaries page to find other compiled software for the SCO OpenServer (bash, rsync, Python, lzop, …) along with notes on running these systems day to day.