Latest update.
This commit is contained in:
+25
-54
@@ -7,6 +7,9 @@ openssl-ts - Time Stamping Authority tool (client/server)
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
B<openssl> B<ts>
|
||||
B<-help>
|
||||
|
||||
B<openssl> B<ts>
|
||||
B<-query>
|
||||
[B<-config> I<configfile>]
|
||||
@@ -33,6 +36,7 @@ B<-reply>
|
||||
[B<-chain> I<certs_file.pem>]
|
||||
[B<-tspolicy> I<object_id>]
|
||||
[B<-in> I<response.tsr>]
|
||||
[B<-untrusted> I<file>]
|
||||
[B<-token_in>]
|
||||
[B<-out> I<response.tsr>]
|
||||
[B<-token_out>]
|
||||
@@ -46,42 +50,10 @@ B<-verify>
|
||||
[B<-queryfile> I<request.tsq>]
|
||||
[B<-in> I<response.tsr>]
|
||||
[B<-token_in>]
|
||||
[B<-CApath> I<trusted_cert_path>]
|
||||
[B<-CAfile> I<trusted_certs.pem>]
|
||||
[B<-CAstore> I<trusted_certs_uri>]
|
||||
[B<-untrusted> I<cert_file.pem>]
|
||||
[I<verify options>]
|
||||
|
||||
I<verify options:>
|
||||
[B<-attime> I<timestamp>]
|
||||
[B<-check_ss_sig>]
|
||||
[B<-crl_check>]
|
||||
[B<-crl_check_all>]
|
||||
[B<-explicit_policy>]
|
||||
[B<-extended_crl>]
|
||||
[B<-ignore_critical>]
|
||||
[B<-inhibit_any>]
|
||||
[B<-inhibit_map>]
|
||||
[B<-issuer_checks>]
|
||||
[B<-no_alt_chains>]
|
||||
[B<-no_check_time>]
|
||||
[B<-partial_chain>]
|
||||
[B<-policy> I<arg>]
|
||||
[B<-policy_check>]
|
||||
[B<-policy_print>]
|
||||
[B<-purpose> I<purpose>]
|
||||
[B<-suiteB_128>]
|
||||
[B<-suiteB_128_only>]
|
||||
[B<-suiteB_192>]
|
||||
[B<-trusted_first>]
|
||||
[B<-use_deltas>]
|
||||
[B<-auth_level> I<num>]
|
||||
[B<-verify_depth> I<num>]
|
||||
[B<-verify_email> I<email>]
|
||||
[B<-verify_hostname> I<hostname>]
|
||||
[B<-verify_ip> I<ip>]
|
||||
[B<-verify_name> I<name>]
|
||||
[B<-x509_strict>]
|
||||
[B<-CAfile> I<file>]
|
||||
[B<-CApath> I<dir>]
|
||||
[B<-CAstore> I<uri>]
|
||||
{- $OpenSSL::safe::opt_v_synopsis -}
|
||||
|
||||
=for openssl ifdef engine
|
||||
|
||||
@@ -128,6 +100,14 @@ requests either by ftp or e-mail.
|
||||
|
||||
=head1 OPTIONS
|
||||
|
||||
=over 4
|
||||
|
||||
=item B<-help>
|
||||
|
||||
Print out a usage message.
|
||||
|
||||
=back
|
||||
|
||||
=head2 Timestamp Request generation
|
||||
|
||||
The B<-query> switch can be used for creating and printing a timestamp
|
||||
@@ -344,12 +324,6 @@ This flag can be used together with the B<-in> option and indicates
|
||||
that the input is a DER encoded timestamp token (ContentInfo) instead
|
||||
of a timestamp response (TimeStampResp). (Optional)
|
||||
|
||||
=item B<-CAfile> I<file>, B<-CApath> I<dir>, B<-CAstore> I<uri>
|
||||
|
||||
See L<openssl(1)/Trusted Certificate Options> for more information.
|
||||
|
||||
At least one of B<-CApath>, B<-CAfile> or B<-CAstore> must be specified.
|
||||
|
||||
=item B<-untrusted> I<cert_file.pem>
|
||||
|
||||
Set of additional untrusted certificates in PEM format which may be
|
||||
@@ -358,17 +332,14 @@ certificate. This file must contain the TSA signing certificate and
|
||||
all intermediate CA certificates unless the response includes them.
|
||||
(Optional)
|
||||
|
||||
=item I<verify options>
|
||||
=item B<-CAfile> I<file>, B<-CApath> I<dir>, B<-CAstore> I<uri>
|
||||
|
||||
The options B<-attime>, B<-check_ss_sig>, B<-crl_check>,
|
||||
B<-crl_check_all>, B<-explicit_policy>, B<-extended_crl>, B<-ignore_critical>,
|
||||
B<-inhibit_any>, B<-inhibit_map>, B<-issuer_checks>, B<-no_alt_chains>,
|
||||
B<-no_check_time>, B<-partial_chain>, B<-policy>, B<-policy_check>,
|
||||
B<-policy_print>, B<-purpose>, B<-suiteB_128>, B<-suiteB_128_only>,
|
||||
B<-suiteB_192>, B<-trusted_first>, B<-use_deltas>, B<-auth_level>,
|
||||
B<-verify_depth>, B<-verify_email>, B<-verify_hostname>, B<-verify_ip>,
|
||||
B<-verify_name>, and B<-x509_strict> can be used to control timestamp
|
||||
verification. See L<openssl-verify(1)>.
|
||||
See L<openssl(1)/Trusted Certificate Options> for details.
|
||||
At least one of B<-CApath>, B<-CAfile> or B<-CAstore> must be specified.
|
||||
|
||||
{- $OpenSSL::safe::opt_v_item -}
|
||||
|
||||
Any verification errors cause the command to exit.
|
||||
|
||||
=back
|
||||
|
||||
@@ -608,7 +579,7 @@ You could also look at the 'test' directory for more examples.
|
||||
|
||||
=head1 BUGS
|
||||
|
||||
=for openssl foreign manuals: procmail(1), perl(1)
|
||||
=for openssl foreign manual procmail(1) perl(1)
|
||||
|
||||
=over 2
|
||||
|
||||
@@ -653,7 +624,7 @@ retained mainly for compatibility reasons.
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<openssl(1)>,
|
||||
L<openssl-tsget(1)>,
|
||||
L<tsget(1)>,
|
||||
L<openssl-req(1)>,
|
||||
L<openssl-x509(1)>,
|
||||
L<openssl-ca(1)>,
|
||||
|
||||
Reference in New Issue
Block a user