diff --git a/doc/man1/ciphers.pod b/doc/man1/ciphers.pod index 129f7660..1fe21877 100644 --- a/doc/man1/ciphers.pod +++ b/doc/man1/ciphers.pod @@ -405,6 +405,21 @@ permissible. =back +=head1 EQUAL PREFERENCE GROUPS + +If configuring a server, one may also configure equal-preference groups to +partially respect the client's preferences when +B is enabled. Ciphers in an equal-preference +group have equal priority and use the client order. This may be used to +enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305 +based on client preferences. An equal-preference is specified with square +brackets, combining multiple selectors separated by |. For example: + + [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256] + + Once an equal-preference group is used, future directives must be + opcode-less. + =head1 CIPHER SUITE NAMES The following lists give the SSL or TLS cipher suites names from the diff --git a/doc/test.patch b/doc/test.patch new file mode 100644 index 00000000..3ed14c6f --- /dev/null +++ b/doc/test.patch @@ -0,0 +1,24 @@ +--- ciphers.pod 2018-04-09 02:53:14.337756676 +0900 ++++ ciphers2.pod 2018-04-09 02:53:03.060663965 +0900 +@@ -405,6 +405,21 @@ + + =back + ++=head1 EQUAL PREFERENCE GROUPS ++ ++If configuring a server, one may also configure equal-preference groups to ++partially respect the client's preferences when ++B is enabled. Ciphers in an equal-preference ++group have equal priority and use the client order. This may be used to ++enforce that AEADs are preferred but select AES-GCM vs. ChaCha20-Poly1305 ++based on client preferences. An equal-preference is specified with square ++brackets, combining multiple selectors separated by |. For example: ++ ++ [ECDHE-ECDSA-CHACHA20-POLY1305|ECDHE-ECDSA-AES128-GCM-SHA256] ++ ++ Once an equal-preference group is used, future directives must be ++ opcode-less. ++ + =head1 CIPHER SUITE NAMES + + The following lists give the SSL or TLS cipher suites names from the