Latest update.
This commit is contained in:
@@ -41,6 +41,7 @@ B<openssl> B<s_server>
|
||||
[B<-no_resume_ephemeral>]
|
||||
[B<-www>]
|
||||
[B<-WWW>]
|
||||
[B<-http_server_binmode>]
|
||||
[B<-servername>]
|
||||
[B<-servername_fatal>]
|
||||
[B<-cert2> I<infile>]
|
||||
@@ -50,6 +51,7 @@ B<openssl> B<s_server>
|
||||
[B<-id_prefix> I<val>]
|
||||
[B<-keymatexport> I<val>]
|
||||
[B<-keymatexportlen> I<+int>]
|
||||
[B<-CRLform> B<DER>|B<PEM>]
|
||||
[B<-CRL> I<infile>]
|
||||
[B<-crl_download>]
|
||||
[B<-cert_chain> I<infile>]
|
||||
@@ -87,7 +89,6 @@ B<openssl> B<s_server>
|
||||
[B<-no_comp>]
|
||||
[B<-comp>]
|
||||
[B<-no_ticket>]
|
||||
[B<-num_tickets>]
|
||||
[B<-serverpref>]
|
||||
[B<-legacy_renegotiation>]
|
||||
[B<-no_renegotiation>]
|
||||
@@ -107,36 +108,6 @@ B<openssl> B<s_server>
|
||||
[B<-dhparam> I<infile>]
|
||||
[B<-record_padding> I<val>]
|
||||
[B<-debug_broken_protocol>]
|
||||
[B<-policy> I<val>]
|
||||
[B<-purpose> I<val>]
|
||||
[B<-verify_name> I<val>]
|
||||
[B<-verify_depth> I<int>]
|
||||
[B<-auth_level> I<int>]
|
||||
[B<-attime> I<intmax>]
|
||||
[B<-verify_hostname> I<val>]
|
||||
[B<-verify_email> I<val>]
|
||||
[B<-verify_ip>]
|
||||
[B<-ignore_critical>]
|
||||
[B<-issuer_checks>]
|
||||
[B<-crl_check>]
|
||||
[B<-crl_check_all>]
|
||||
[B<-policy_check>]
|
||||
[B<-explicit_policy>]
|
||||
[B<-inhibit_any>]
|
||||
[B<-inhibit_map>]
|
||||
[B<-x509_strict>]
|
||||
[B<-extended_crl>]
|
||||
[B<-use_deltas>]
|
||||
[B<-policy_print>]
|
||||
[B<-check_ss_sig>]
|
||||
[B<-trusted_first>]
|
||||
[B<-suiteB_128_only>]
|
||||
[B<-suiteB_128>]
|
||||
[B<-suiteB_192>]
|
||||
[B<-partial_chain>]
|
||||
[B<-no_alt_chains>]
|
||||
[B<-no_check_time>]
|
||||
[B<-allow_proxy_certs>]
|
||||
[B<-nbio>]
|
||||
[B<-psk_identity> I<val>]
|
||||
[B<-psk_hint> I<val>]
|
||||
@@ -154,13 +125,17 @@ B<openssl> B<s_server>
|
||||
[B<-use_srtp> I<val>]
|
||||
[B<-alpn> I<val>]
|
||||
[B<-keylogfile> I<outfile>]
|
||||
[B<-recv_max_early_data> I<int>]
|
||||
[B<-max_early_data> I<int>]
|
||||
[B<-early_data>]
|
||||
[B<-stateless>]
|
||||
[B<-anti_replay>]
|
||||
[B<-no_anti_replay>]
|
||||
[B<-http_server_binmode>]
|
||||
[B<-num_tickets>]
|
||||
{- $OpenSSL::safe::opt_name_synopsis -}
|
||||
{- $OpenSSL::safe::opt_version_synopsis -}
|
||||
{- $OpenSSL::safe::opt_v_synopsis -}
|
||||
{- $OpenSSL::safe::opt_s_synopsis -}
|
||||
{- $OpenSSL::safe::opt_x_synopsis -}
|
||||
{- $OpenSSL::safe::opt_trust_synopsis -}
|
||||
{- $OpenSSL::safe::opt_r_synopsis -}
|
||||
@@ -397,6 +372,11 @@ In addition, the special URL C</stats> will return status
|
||||
information like the B<-www> option.
|
||||
Neither of these options can be used in conjunction with B<-early_data>.
|
||||
|
||||
=item B<-http_server_binmode>
|
||||
|
||||
When acting as web-server (using option B<-WWW> or B<-HTTP>) open files requested
|
||||
by the client in binary mode.
|
||||
|
||||
=item B<-id_prefix> I<val>
|
||||
|
||||
Generate SSL/TLS session IDs prefixed by I<val>. This is mostly useful
|
||||
@@ -565,23 +545,6 @@ load the parameters from the server certificate file.
|
||||
If this fails then a static set of parameters hard coded into this command
|
||||
will be used.
|
||||
|
||||
=item B<-attime>, B<-check_ss_sig>, B<-crl_check>, B<-crl_check_all>,
|
||||
B<-explicit_policy>, B<-extended_crl>, B<-ignore_critical>, B<-inhibit_any>,
|
||||
B<-inhibit_map>, B<-no_alt_chains>, B<-no_check_time>, B<-partial_chain>, B<-policy>,
|
||||
B<-policy_check>, B<-policy_print>, B<-purpose>, B<-suiteB_128>,
|
||||
B<-suiteB_128_only>, B<-suiteB_192>, B<-trusted_first>, B<-use_deltas>,
|
||||
B<-auth_level>, B<-verify_depth>, B<-verify_email>, B<-verify_hostname>,
|
||||
B<-verify_ip>, B<-verify_name>, B<-x509_strict>
|
||||
|
||||
Set different peer certificate verification options.
|
||||
See the L<openssl-verify(1)> manual page for details.
|
||||
|
||||
=item B<-crl_check>, B<-crl_check_all>
|
||||
|
||||
Check the peer certificate has not been revoked by its CA.
|
||||
The CRL(s) are appended to the certificate file. With the B<-crl_check_all>
|
||||
option all CRLs of all CAs in the chain are checked.
|
||||
|
||||
=item B<-nbio>
|
||||
|
||||
Turns on non blocking I/O.
|
||||
@@ -661,11 +624,20 @@ and any incoming early data (when used in conjunction with the B<-early_data>
|
||||
flag). The default value is approximately 16k. The argument must be an integer
|
||||
greater than or equal to 0.
|
||||
|
||||
=item B<-recv_max_early_data> I<int>
|
||||
|
||||
Specify the hard limit on the maximum number of early data bytes that will
|
||||
be accepted.
|
||||
|
||||
=item B<-early_data>
|
||||
|
||||
Accept early data where possible. Cannot be used in conjunction with B<-www>,
|
||||
B<-WWW>, B<-HTTP> or B<-rev>.
|
||||
|
||||
=item B<-stateless>
|
||||
|
||||
Require TLSv1.3 cookies.
|
||||
|
||||
=item B<-anti_replay>, B<-no_anti_replay>
|
||||
|
||||
Switches replay protection on or off, respectively. Replay protection is on by
|
||||
@@ -675,15 +647,12 @@ has been negotiated, and early data is enabled on the server. A full handshake
|
||||
is forced if a session ticket is used a second or subsequent time. Any early
|
||||
data that was sent will be rejected.
|
||||
|
||||
=item B<-http_server_binmode>
|
||||
|
||||
When acting as web-server (using option B<-WWW> or B<-HTTP>) open files requested
|
||||
by the client in binary mode.
|
||||
|
||||
{- $OpenSSL::safe::opt_name_item -}
|
||||
|
||||
{- $OpenSSL::safe::opt_version_item -}
|
||||
|
||||
{- $OpenSSL::safe::opt_s_item -}
|
||||
|
||||
{- $OpenSSL::safe::opt_x_item -}
|
||||
|
||||
{- $OpenSSL::safe::opt_trust_item -}
|
||||
@@ -692,6 +661,12 @@ by the client in binary mode.
|
||||
|
||||
{- $OpenSSL::safe::opt_engine_item -}
|
||||
|
||||
{- $OpenSSL::safe::opt_v_item -}
|
||||
|
||||
If the server requests a client certificate, then
|
||||
verification errors are displayed, for debugging, but the command will
|
||||
proceed unless the B<-verify_return_error> option is used.
|
||||
|
||||
=back
|
||||
|
||||
=head1 CONNECTED COMMANDS
|
||||
|
||||
Reference in New Issue
Block a user