Latest update (add quic)

This commit is contained in:
2020-07-12 19:52:18 +09:00
parent 3a6d64bb68
commit e85ee33eee
501 changed files with 19166 additions and 10232 deletions
+2 -2
View File
@@ -113,7 +113,7 @@ written to standard output.
=item B<-signCA>
This option is the same as the B<-signreq> option except it uses the
This option is the same as the B<-sign> option except it uses the
configuration file section B<v3_ca> and so makes the signed request a
valid CA certificate. This is useful when creating intermediate CA from
a root CA. Extra params are passed to L<openssl-ca(1)>.
@@ -165,7 +165,7 @@ the request and finally create a PKCS#12 file containing it.
CA.pl -newca
CA.pl -newreq
CA.pl -signreq
CA.pl -sign
CA.pl -pkcs12 "My Test Certificate"
=head1 ENVIRONMENT
+7
View File
@@ -403,6 +403,13 @@ used and only the two suite B compliant cipher suites
(ECDHE-ECDSA-AES128-GCM-SHA256 and ECDHE-ECDSA-AES256-GCM-SHA384) are
permissible.
=item B<CBC>
All cipher suites using encryption algorithm in Cipher Block Chaining (CBC)
mode. These cipher suites are only supported in TLS v1.2 and earlier. Currently
it's an alias for the following cipherstrings: B<SSL_DES>, B<SSL_3DES>, B<SSL_RC2>,
B<SSL_IDEA>, B<SSL_AES128>, B<SSL_AES256>, B<SSL_CAMELLIA128>, B<SSL_CAMELLIA256>, B<SSL_SEED>.
=back
=head1 EQUAL PREFERENCE GROUPS
+50 -59
View File
@@ -151,7 +151,7 @@ The B<cmp> command is a client implementation for the Certificate
Management Protocol (CMP) as defined in RFC4210.
It can be used to request certificates from a CA server,
update their certificates,
request certificates to be revoked, and perform other CMP requests.
request certificates to be revoked, and perform other types of CMP requests.
=head1 OPTIONS
@@ -206,16 +206,16 @@ Currently implemented commands are:
=back
B<ir> requests initialization of an End Entity into a PKI hierarchy by means of
issuance of a first certificate.
B<ir> requests initialization of an End Entity into a PKI hierarchy
by issuing a first certificate.
B<cr> requests issuance of an additional certificate for an End Entity already
B<cr> requests issuing an additional certificate for an End Entity already
initialized to the PKI hierarchy.
B<p10cr> requests issuance of an additional certificate similarly to B<cr>
B<p10cr> requests issuing an additional certificate similarly to B<cr>
but uses PKCS#10 CSR format.
B<kur> requests (key) update for an existing, given certificate.
B<kur> requests a (key) update for an existing, given certificate.
B<rr> requests revocation of an existing, given certificate.
@@ -268,8 +268,8 @@ This default is used for IR and CR only if no SANs are set.
The argument must be formatted as I</type0=value0/type1=value1/type2=...>,
characters may be escaped by C<\>E<nbsp>(backslash), no spaces are skipped.
In case B<-cert> is not set, for instance when using MSG_MAC_ALG,
the subject DN is also used as sender of the PKI message.
The subject DN is also used as fallback sender of outgoing CMP messages
if no B<-cert> and no B<-oldcert> are given.
=item B<-issuer> I<name>
@@ -393,8 +393,9 @@ It must be given for RR, while for KUR it defaults to B<-cert>.
The reference certificate determined in this way, if any, is also used for
deriving default subject DN and Subject Alternative Names for IR, CR, and KUR.
Its issuer, if any, is used as default recipient in the CMP message header
if neither B<-srvcert>, B<-recipient>, nor B<-issuer> is available.
Its subject is used as sender of outgoing messages if B<-cert> is not given.
Its issuer is used as default recipient in CMP message headers
if neither B<-recipient>, B<-srvcert>, nor B<-issuer> is given.
=item B<-revreason> I<number>
@@ -428,13 +429,13 @@ Reason numbers defined in RFC 5280 are:
The IP address or DNS hostname and optionally port (defaulting to 80 or 443)
of the CMP server to connect to using HTTP(S) transport.
The optional "http://" or "https://" prefix is ignored.
The optional I<http://> or I<https://> prefix is ignored.
=item B<-proxy> I<[http[s]://]address[:port][/path]>
The HTTP(S) proxy server to use for reaching the CMP server unless B<no_proxy>
applies, see below.
The optional "http://" or "https://" prefix and any trailing path are ignored.
The optional I<http://> or I<https://> prefix and any trailing path are ignored.
Defaults to the environment variable C<http_proxy> if set, else C<HTTP_PROXY>
in case no TLS is used, otherwise C<https_proxy> if set, else C<HTTPS_PROXY>.
@@ -447,7 +448,7 @@ Default is from the environment variable C<no_proxy> if set, else C<NO_PROXY>.
=item B<-path> I<remote_path>
HTTP path at the CMP server (aka CMP alias) to use for POST requests.
Defaults to "/".
Defaults to I</>.
=item B<-msg_timeout> I<seconds>
@@ -473,8 +474,9 @@ Default is 0 (infinite).
When verifying signature-based protection of CMP response messages,
these are the CA certificate(s) to trust while checking certificate chains
during CMP server authentication.
This option gives more flexibility than the B<-srvcert> option because
it does not pin down the expected CMP server by allowing only one certificate.
This option gives more flexibility than the B<-srvcert> option because the
protection certificate is not pinned but may be any certificate
for which a chain to one of the given trusted certificates can be constructed.
Multiple filenames may be given, separated by commas and/or whitespace
(where in the latter case the whole argument must be enclosed in "...").
@@ -482,65 +484,55 @@ Each source may contain multiple certificates.
=item B<-untrusted> I<sources>
Non-trusted intermediate certificate(s) that may be useful
for constructing the TLS client certificate chain (if TLS is enabled) and
for building certificate chains while verifying the CMP server certificate
(when checking signature-based CMP message protection)
and while verifying the newly enrolled certificate.
These may get added to the extraCerts field sent in requests as far as needed.
Non-trusted intermediate CA certificate(s) that may be useful for cert path
construction for the CMP client certificate (to include in the extraCerts field
of outgoing messages), for the TLS client certificate (if TLS is enabled),
when verifying the CMP server certificate (checking signature-based
CMP message protection), and when verifying newly enrolled certificates.
Multiple filenames may be given, separated by commas and/or whitespace.
Each file may contain multiple certificates.
=item B<-srvcert> I<filename>
The specific CMP server certificate to use and directly trust (even if it is
The specific CMP server certificate to expect and directly trust (even if it is
expired) when verifying signature-based protection of CMP response messages.
May be set alternatively to the B<-trusted> option
if the certificate is available and only this one shall be accepted.
May be set alternatively to the B<-trusted> option to pin the accepted server.
If set, the issuer of the certificate is also used as the recipient of the CMP
request and as the expected sender of the CMP response,
overriding any potential B<-recipient> option.
If set, the subject of the certificate is also used
as default value for the recipient of CMP requests
and as default value for the expected sender of incoming CMP messages.
=item B<-recipient> I<name>
This option may be used to explicitly set the Distinguished Name (DN)
of the CMP message recipient, i.e., the CMP server (usually a CA or RA entity).
Distinguished Name (DN) to use in the recipient field of CMP request messages,
i.e., the CMP server (usually a CA or RA entity).
The argument must be formatted as I</type0=value0/type1=value1/type2=...>,
characters may be escaped by C<\>E<nbsp>(backslash), no spaces are skipped.
If a CMP server certificate is given with the B<-srvcert> option, its subject
name is taken as the recipient name and the B<-recipient> option is ignored.
If neither of the two are given, the recipient of the PKI message is
determined in the following order: from the B<-issuer> option if present,
the issuer of old cert given with the B<-oldcert> option if present,
the issuer of the client certificate (B<-cert> option) if present.
The recipient field in the header of CMP messagese is mandatory.
If none of the options that enable the derivation of the recipient name are
given, no suitable value for the recipient in the PKIHeader is available.
As a last resort it is set to NULL-DN.
When a response is received, its sender must match the recipient of the request.
The recipient field in the header of a CMP message is mandatory.
If not given explicitly the recipient is determined in the following order:
the subject of the CMP server certificate given with the B<-srvcert> option,
the B<-issuer> option,
the issuer of the certificate given with the B<-oldcert> option,
the issuer of the CMP client certificate (B<-cert> option),
as far as any of those is present, else the NULL-DN as last resort.
=item B<-expect_sender> I<name>
Distinguished Name (DN) of the expected sender of CMP response messages when
MSG_SIG_ALG is used for protection.
This can be used to ensure that only a particular entity is accepted
as the CMP server, and attackers are not able to use arbitrary certificates
of a trusted PKI hierarchy to fraudulently pose as a CMP server.
Note that this option gives slightly more freedom than B<-srvcert>,
which pins down the server to a particular certificate,
while B<-expect_sender> I<name> will continue to match after updates of the
server cert.
Distinguished Name (DN) expected in the sender field of incoming CMP messages.
Defaults to the subject DN of the pinned B<-srvcert>, if any.
The argument must be formatted as I</type0=value0/type1=value1/type2=...>,
characters may be escaped by C<\>E<nbsp>(backslash), no spaces are skipped.
If not given, the subject DN of B<-srvcert>, if provided, will be used.
This can be used to make sure that only a particular entity is accepted as
CMP message signer, and attackers are not able to use arbitrary certificates
of a trusted PKI hierarchy to fraudulently pose as a CMP server.
Note that this option gives slightly more freedom than setting the B<-srvcert>,
which pins the server to the holder of a particular certificate, while the
expected sender name will continue to match after updates of the server cert.
=item B<-ignore_keyusage>
@@ -621,8 +613,8 @@ B<PASS PHRASE ARGUMENTS> section in L<openssl(1)>.
The client's current certificate.
Requires the corresponding key to be given with B<-key>.
The subject of this certificate will be used as the "sender" field
of outgoing CMP messages, while B<-subjectName> may provide a fallback value.
The subject of this certificate will be used as sender of outgoing CMP messages,
while the subject of B<-oldcert> or B<-subjectName> may provide fallback values.
When using signature-based message protection, this "protection certificate"
will be included first in the extraCerts field of outgoing messages.
In Initialization Request (IR) messages this can be used for authenticating
@@ -630,7 +622,6 @@ using an external entity certificate as defined in appendix E.7 of RFC 4210.
For Key Update Request (KUR) messages this is also used as
the certificate to be updated if the B<-oldcert> option is not given.
If the file includes further certs, they are appended to the untrusted certs.
These may get added to the extraCerts field sent in requests as far as needed.
=item B<-key> I<filename>
@@ -740,8 +731,8 @@ when connecting to CMP server.
=item B<-tls_cert> I<filename>
Client's TLS certificate.
If the file includes further certificates,
they are used for constructing the client cert chain provided to the TLS server.
If the file includes further certs they are used (along with B<-untrusted>
certs) for constructing the client cert chain provided to the TLS server.
=item B<-tls_key> I<filename>
@@ -1015,7 +1006,7 @@ the CMP command-line argument B<-proxy>, for example
-proxy http://192.168.1.1:8080
In the Insta Demo CA scenario both clients and the server may use the pre-shared
secret "insta" and the reference value "3078" to authenticate to each other.
secret I<insta> and the reference value I<3078> to authenticate to each other.
Alternatively, CMP messages may be protected in signature-based manner,
where the trust anchor in this case is F<insta.ca.crt>
@@ -1060,7 +1051,7 @@ and/or on the command line.
The following examples at first do not make use of a configuration file.
They assume that a CMP server can be contacted on the local TCP port 80
and accepts requests under the alias "/pkix/".
and accepts requests under the alias I</pkix/>.
For enrolling its very first certificate the client generates a first client key
and sends an initial request message to the local CMP server
+6 -4
View File
@@ -569,7 +569,8 @@ Message-digest of the eContent OCTET STRING within encapContentInfo being signed
=item *
An ESS signing-certificate or ESS signing-certificate-v2 attribute, as defined in Enhanced Security Services (ESS), RFC 2634 and RFC 5035.
An ESS signing-certificate or ESS signing-certificate-v2 attribute, as defined
in Enhanced Security Services (ESS), RFC 2634 and RFC 5035.
An ESS signing-certificate attribute only allows for the use of SHA-1 as a digest algorithm.
An ESS signing-certificate-v2 attribute allows for the use of any digest algorithm.
@@ -577,9 +578,10 @@ An ESS signing-certificate-v2 attribute allows for the use of any digest algorit
The digital signature value computed on the user data and, when present, on the signed attributes.
Note that currently the B<-cades> option applies only to the B<-sign> operation and is ignored during
the B<-verify> operation, i.e. the signing certification is not checked during the verification process.
This feature might be added in a future version.
NOTE that the B<-cades> option applies to the B<-sign> or B<-verify> operations.
With this option, the B<-verify> operation also checks that the signing-certificates
attribute is present, and its value matches the verification trust chain built
during the verification process.
=back
+26 -22
View File
@@ -25,20 +25,26 @@ B<openssl fipsinstall>
=head1 DESCRIPTION
This command is used to generate a FIPS module configuration file.
This configuration file can be used each time a FIPS module is loaded
in order to pass data to the FIPS module self tests. The FIPS module always
verifies its MAC, but only needs to run the KAT's once,
at installation.
The generated configuration file consists of:
=over 4
=item - A mac of the FIPS module file.
=item - A MAC of the FIPS module file.
=item - A status indicator that indicates if the known answer Self Tests (KAT's)
have successfully run.
=item - A test status indicator.
This indicates if the Known Answer Self Tests (KAT's) have successfully run.
=item - A MAC of the status indicator.
=back
This configuration file can be used each time a FIPS module is loaded
in order to pass data to the FIPS modules self tests. The FIPS module always
verifies the modules MAC, but only needs to run the KATS once during install.
This file is described in L<fips_config(5)>.
=head1 OPTIONS
@@ -50,32 +56,36 @@ Print a usage message.
=item B<-module> I<filename>
Filename of a fips module to perform an integrity check on.
Filename of the FIPS module to perform an integrity check on.
=item B<-out> I<configfilename>
Filename to output the configuration data to, or standard output by default.
Filename to output the configuration data to; the default is standard output.
=item B<-in> I<configfilename>
Input filename to load configuration data from. Used with the '-verify' option.
Standard input is used if the filename is '-'.
Input filename to load configuration data from. Used with the B<-verify> option.
Standard input is used if the filename is C<->.
=item B<-verify>
Verify that the input configuration file contains the correct information
Verify that the input configuration file contains the correct information.
=item B<-provider_name> I<providername>
Name of the provider inside the configuration file.
This must be specified.
=item B<-section_name> I<sectionname>
Name of the section inside the configuration file.
This must be specified.
=item B<-mac_name> I<name>
Specifies the name of a supported MAC algorithm which will be used.
The MAC mechanisms that are available will depend on the options
used when building OpenSSL.
To see the list of supported MAC's use the command
C<openssl list -mac-algorithms>. The default is B<HMAC>.
@@ -122,10 +132,10 @@ Do not output pass/fail messages. Implies B<-noout>.
=item B<-corrupt_desc> I<selftest_description>,
B<-corrupt_type> I<selftest_type>
The corrupt options can be used to test failure of one or more self test(s) by
The corrupt options can be used to test failure of one or more self tests by
name.
Either option or both may be used to select the self test(s) to corrupt.
Refer to the entries for "st-desc" and "st-type" in L<OSSL_PROVIDER-FIPS(7)> for
Either option or both may be used to select the tests to corrupt.
Refer to the entries for B<st-desc> and B<st-type> in L<OSSL_PROVIDER-FIPS(7)> for
values that can be used.
=back
@@ -145,18 +155,12 @@ Verify that the configuration file F<fips.cnf> contains the correct info:
-section_name fips_install -mac_name HMAC -macopt digest:SHA256 \
-macopt hexkey:000102030405060708090A0B0C0D0E0F10111213 -verify
Corrupt any self tests which have the description 'SHA1':
Corrupt any self tests which have the description C<SHA1>:
openssl fipsinstall -module ./fips.so -out fips.cnf -provider_name fips \
-section_name fipsinstall -mac_name HMAC -macopt digest:SHA256 \
-macopt hexkey:000102030405060708090A0B0C0D0E0F10111213 \
-corrupt_desc', 'SHA1'
=head1 NOTES
The MAC mechanisms that are available will depend on the options
used when building OpenSSL.
The command C<openssl list -mac-algorithms> command can be used to list them.
-corrupt_desc 'SHA1'
=head1 SEE ALSO
+2 -1
View File
@@ -33,7 +33,7 @@ B<openssl> B<genrsa>
{- $OpenSSL::safe::opt_provider_synopsis -}
[B<numbits>]
=for openssl ifdef engine
=for openssl ifdef engine 3
=head1 DESCRIPTION
@@ -70,6 +70,7 @@ for if it is not supplied via the B<-passout> argument.
=item B<-F4>, B<-f4>, B<-3>
The public exponent to use, either 65537 or 3. The default is 65537.
The B<-3> option has been deprecated.
=item B<-primes> I<num>
+1 -1
View File
@@ -46,7 +46,7 @@ Output the derived key in binary form. Uses hexadecimal text format if not speci
Passes options to the KDF algorithm.
A comprehensive list of parameters can be found in the EVP_KDF_CTX
implementation documentation.
Common parameter names used by EVP_KDF_CTX_set_params() are:
Common parameter names used by EVP_KDF_set_ctx_params() are:
=over 4
+1 -1
View File
@@ -49,7 +49,7 @@ Output the MAC in binary form. Uses hexadecimal text format if not specified.
Passes options to the MAC algorithm.
A comprehensive list of controls can be found in the EVP_MAC implementation
documentation.
Common parameter names used by EVP_MAC_CTX_get_params() are:
Common parameter names used by EVP_MAC_get_ctx_params() are:
=over 4
+10
View File
@@ -78,6 +78,7 @@ B<openssl> B<s_client>
[B<-split_send_frag>]
[B<-max_pipelines>]
[B<-read_buf>]
[B<-ignore_unexpected_eof>]
[B<-bugs>]
[B<-comp>]
[B<-no_comp>]
@@ -578,6 +579,15 @@ effect if the buffer size is larger than the size that would otherwise be used
and pipelining is in use (see L<SSL_CTX_set_default_read_buffer_len(3)> for
further information).
=item B<-ignore_unexpected_eof>
Some TLS implementations do not send the mandatory close_notify alert on
shutdown. If the application tries to wait for the close_notify alert but the
peer closes the connection without sending it, an error is generated. When this
option is enabled the peer does not need to send the close_notify alert and a
closed connection will be treated as if the close_notify alert was received.
For more information on shutting down a connection, see L<SSL_shutdown(3)>.
=item B<-bugs>
There are several known bugs in SSL and TLS implementations. Adding this
+10
View File
@@ -47,6 +47,7 @@ B<openssl> B<s_server>
[B<-WWW>]
[B<-http_server_binmode>]
[B<-no_ca_names>]
[B<-ignore_unexpected_eof>]
[B<-servername>]
[B<-servername_fatal>]
[B<-tlsextdebug>]
@@ -420,6 +421,15 @@ Disable TLS Extension CA Names. You may want to disable it for security reasons
or for compatibility with some Windows TLS implementations crashing when this
extension is larger than 1024 bytes.
=item B<-ignore_unexpected_eof>
Some TLS implementations do not send the mandatory close_notify alert on
shutdown. If the application tries to wait for the close_notify alert but the
peer closes the connection without sending it, an error is generated. When this
option is enabled the peer does not need to send the close_notify alert and a
closed connection will be treated as if the close_notify alert was received.
For more information on shutting down a connection, see L<SSL_shutdown(3)>.
=item B<-id_prefix> I<val>
Generate SSL/TLS session IDs prefixed by I<val>. This is mostly useful
+7 -3
View File
@@ -1298,9 +1298,9 @@ General SSL/TLS.
SSL/TLS cipher.
=item B<ENGINE_CONF>
=item B<CONF>
ENGINE configuration.
Show details about provider and engine configuration.
=item B<ENGINE_TABLE>
@@ -1405,7 +1405,11 @@ The B<-issuer_checks> option is deprecated as of OpenSSL 1.1.0 and
is silently ignored.
The B<-xcertform> and B<-xkeyform> options
are obsolete since OpenSSL 3.0.0 and have no effect.
are obsolete since OpenSSL 3.0 and have no effect.
The interactive mode, which could be invoked by running C<openssl>
with no further arguments, was removed in OpenSSL 3.0, and running
that program with no arguments is now equivalent to C<openssl help>.
=head1 COPYRIGHT