diff options
| author | inoguchi <> | 2019-07-08 14:15:12 +0000 |
|---|---|---|
| committer | inoguchi <> | 2019-07-08 14:15:12 +0000 |
| commit | 2d135fd4559d62f0b0962bf8ed0f4fea9beee71f (patch) | |
| tree | 94dd195ff5f20a29095937aa37d84321440a8db2 /src | |
| parent | e6083e7e4d5f05795e40db857f1e349378012a56 (diff) | |
| download | openbsd-2d135fd4559d62f0b0962bf8ed0f4fea9beee71f.tar.gz openbsd-2d135fd4559d62f0b0962bf8ed0f4fea9beee71f.tar.bz2 openbsd-2d135fd4559d62f0b0962bf8ed0f4fea9beee71f.zip | |
Fix manual openssl(1) dsa, ocsp, rsa and smime
- dsa : add missing -pvk-none, -pvk-strong and -pvk-weak
add pvk format to -inform and -outform
- ocsp : add missing -header, -ignore_err, -no_explicit and -timeout
- rsa : add missing -pvk-none, -pvk-strong and -pvk-weak
add missing -RSAPublicKey_in and -RSAPublicKey_out
add pvk format to -inform and -outform
- smime : add missing -nosmimecap
- add pvk description at common format part
ok jmc@
Diffstat (limited to 'src')
| -rw-r--r-- | src/usr.bin/openssl/openssl.1 | 68 |
1 files changed, 56 insertions, 12 deletions
diff --git a/src/usr.bin/openssl/openssl.1 b/src/usr.bin/openssl/openssl.1 index f935ab1a8a..624c29d0aa 100644 --- a/src/usr.bin/openssl/openssl.1 +++ b/src/usr.bin/openssl/openssl.1 | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | .\" $OpenBSD: openssl.1,v 1.107 2019/07/07 02:04:40 inoguchi Exp $ | 1 | .\" $OpenBSD: openssl.1,v 1.108 2019/07/08 14:15:12 inoguchi Exp $ |
| 2 | .\" ==================================================================== | 2 | .\" ==================================================================== |
| 3 | .\" Copyright (c) 1998-2002 The OpenSSL Project. All rights reserved. | 3 | .\" Copyright (c) 1998-2002 The OpenSSL Project. All rights reserved. |
| 4 | .\" | 4 | .\" |
| @@ -110,7 +110,7 @@ | |||
| 110 | .\" copied and put under another distribution licence | 110 | .\" copied and put under another distribution licence |
| 111 | .\" [including the GNU Public Licence.] | 111 | .\" [including the GNU Public Licence.] |
| 112 | .\" | 112 | .\" |
| 113 | .Dd $Mdocdate: July 7 2019 $ | 113 | .Dd $Mdocdate: July 8 2019 $ |
| 114 | .Dt OPENSSL 1 | 114 | .Dt OPENSSL 1 |
| 115 | .Os | 115 | .Os |
| 116 | .Sh NAME | 116 | .Sh NAME |
| @@ -1184,15 +1184,16 @@ parameters are generated instead. | |||
| 1184 | .Fl des | des3 | 1184 | .Fl des | des3 |
| 1185 | .Oc | 1185 | .Oc |
| 1186 | .Op Fl in Ar file | 1186 | .Op Fl in Ar file |
| 1187 | .Op Fl inform Cm der | pem | 1187 | .Op Fl inform Cm der | pem | pvk |
| 1188 | .Op Fl modulus | 1188 | .Op Fl modulus |
| 1189 | .Op Fl noout | 1189 | .Op Fl noout |
| 1190 | .Op Fl out Ar file | 1190 | .Op Fl out Ar file |
| 1191 | .Op Fl outform Cm der | pem | 1191 | .Op Fl outform Cm der | pem | pvk |
| 1192 | .Op Fl passin Ar arg | 1192 | .Op Fl passin Ar arg |
| 1193 | .Op Fl passout Ar arg | 1193 | .Op Fl passout Ar arg |
| 1194 | .Op Fl pubin | 1194 | .Op Fl pubin |
| 1195 | .Op Fl pubout | 1195 | .Op Fl pubout |
| 1196 | .Op Fl pvk-none | pvk-strong | pvk-weak | ||
| 1196 | .Op Fl text | 1197 | .Op Fl text |
| 1197 | .nr nS 0 | 1198 | .nr nS 0 |
| 1198 | .Pp | 1199 | .Pp |
| @@ -1230,7 +1231,7 @@ These options can only be used with PEM format output files. | |||
| 1230 | The input file to read from, | 1231 | The input file to read from, |
| 1231 | or standard input if not specified. | 1232 | or standard input if not specified. |
| 1232 | If the key is encrypted, a pass phrase will be prompted for. | 1233 | If the key is encrypted, a pass phrase will be prompted for. |
| 1233 | .It Fl inform Cm der | pem | 1234 | .It Fl inform Cm der | pem | pvk |
| 1234 | The input format. | 1235 | The input format. |
| 1235 | .It Fl modulus | 1236 | .It Fl modulus |
| 1236 | Print the value of the public key component of the key. | 1237 | Print the value of the public key component of the key. |
| @@ -1241,7 +1242,7 @@ The output file to write to, | |||
| 1241 | or standard output if not specified. | 1242 | or standard output if not specified. |
| 1242 | If any encryption options are set then a pass phrase will be | 1243 | If any encryption options are set then a pass phrase will be |
| 1243 | prompted for. | 1244 | prompted for. |
| 1244 | .It Fl outform Cm der | pem | 1245 | .It Fl outform Cm der | pem | pvk |
| 1245 | The output format. | 1246 | The output format. |
| 1246 | .It Fl passin Ar arg | 1247 | .It Fl passin Ar arg |
| 1247 | The key password source. | 1248 | The key password source. |
| @@ -1252,6 +1253,12 @@ Read in a public key, not a private key. | |||
| 1252 | .It Fl pubout | 1253 | .It Fl pubout |
| 1253 | Output a public key, not a private key. | 1254 | Output a public key, not a private key. |
| 1254 | Automatically set if the input is a public key. | 1255 | Automatically set if the input is a public key. |
| 1256 | .It Xo | ||
| 1257 | .Fl pvk-none | pvk-strong | pvk-weak | ||
| 1258 | .Xc | ||
| 1259 | Enable or disable PVK encoding. | ||
| 1260 | The default is | ||
| 1261 | .Fl pvk-strong . | ||
| 1255 | .It Fl text | 1262 | .It Fl text |
| 1256 | Print the public/private key in plain text. | 1263 | Print the public/private key in plain text. |
| 1257 | .El | 1264 | .El |
| @@ -1933,7 +1940,9 @@ a Netscape certificate sequence is created from a file of certificates. | |||
| 1933 | .Op Fl CApath Ar directory | 1940 | .Op Fl CApath Ar directory |
| 1934 | .Op Fl cert Ar file | 1941 | .Op Fl cert Ar file |
| 1935 | .Op Fl dgst Ar alg | 1942 | .Op Fl dgst Ar alg |
| 1943 | .Op Fl header Ar name value | ||
| 1936 | .Op Fl host Ar hostname : Ns Ar port | 1944 | .Op Fl host Ar hostname : Ns Ar port |
| 1945 | .Op Fl ignore_err | ||
| 1937 | .Op Fl index Ar indexfile | 1946 | .Op Fl index Ar indexfile |
| 1938 | .Op Fl issuer Ar file | 1947 | .Op Fl issuer Ar file |
| 1939 | .Op Fl ndays Ar days | 1948 | .Op Fl ndays Ar days |
| @@ -1942,6 +1951,7 @@ a Netscape certificate sequence is created from a file of certificates. | |||
| 1942 | .Op Fl no_cert_verify | 1951 | .Op Fl no_cert_verify |
| 1943 | .Op Fl no_certs | 1952 | .Op Fl no_certs |
| 1944 | .Op Fl no_chain | 1953 | .Op Fl no_chain |
| 1954 | .Op Fl no_explicit | ||
| 1945 | .Op Fl no_intern | 1955 | .Op Fl no_intern |
| 1946 | .Op Fl no_nonce | 1956 | .Op Fl no_nonce |
| 1947 | .Op Fl no_signature_verify | 1957 | .Op Fl no_signature_verify |
| @@ -1962,12 +1972,13 @@ a Netscape certificate sequence is created from a file of certificates. | |||
| 1962 | .Op Fl rkey Ar file | 1972 | .Op Fl rkey Ar file |
| 1963 | .Op Fl rother Ar file | 1973 | .Op Fl rother Ar file |
| 1964 | .Op Fl rsigner Ar file | 1974 | .Op Fl rsigner Ar file |
| 1965 | .Op Fl serial Ar number | 1975 | .Op Fl serial Ar num |
| 1966 | .Op Fl sign_other Ar file | 1976 | .Op Fl sign_other Ar file |
| 1967 | .Op Fl signer Ar file | 1977 | .Op Fl signer Ar file |
| 1968 | .Op Fl signkey Ar file | 1978 | .Op Fl signkey Ar file |
| 1969 | .Op Fl status_age Ar age | 1979 | .Op Fl status_age Ar age |
| 1970 | .Op Fl text | 1980 | .Op Fl text |
| 1981 | .Op Fl timeout Ar seconds | ||
| 1971 | .Op Fl trust_other | 1982 | .Op Fl trust_other |
| 1972 | .Op Fl url Ar responder_url | 1983 | .Op Fl url Ar responder_url |
| 1973 | .Op Fl VAfile Ar file | 1984 | .Op Fl VAfile Ar file |
| @@ -2016,6 +2027,10 @@ on | |||
| 2016 | specifies the HTTP path name to use, or | 2027 | specifies the HTTP path name to use, or |
| 2017 | .Pa / | 2028 | .Pa / |
| 2018 | by default. | 2029 | by default. |
| 2030 | .It Fl header Ar name value | ||
| 2031 | Add the header name with the specified value to the OCSP request that is sent | ||
| 2032 | to the responder. | ||
| 2033 | This may be repeated. | ||
| 2019 | .It Fl issuer Ar file | 2034 | .It Fl issuer Ar file |
| 2020 | The current issuer certificate, in PEM format. | 2035 | The current issuer certificate, in PEM format. |
| 2021 | Can be used multiple times and must come before any | 2036 | Can be used multiple times and must come before any |
| @@ -2035,6 +2050,8 @@ Don't include any certificates in the signed request. | |||
| 2035 | .It Fl no_chain | 2050 | .It Fl no_chain |
| 2036 | Do not use certificates in the response as additional untrusted CA | 2051 | Do not use certificates in the response as additional untrusted CA |
| 2037 | certificates. | 2052 | certificates. |
| 2053 | .It Fl no_explicit | ||
| 2054 | Don't check the explicit trust for OCSP signing in the root CA certificate. | ||
| 2038 | .It Fl no_intern | 2055 | .It Fl no_intern |
| 2039 | Ignore certificates contained in the OCSP response | 2056 | Ignore certificates contained in the OCSP response |
| 2040 | when searching for the signer's certificate. | 2057 | when searching for the signer's certificate. |
| @@ -2109,6 +2126,8 @@ If the | |||
| 2109 | option is not present, then the private key is read from the same file | 2126 | option is not present, then the private key is read from the same file |
| 2110 | as the certificate. | 2127 | as the certificate. |
| 2111 | If neither option is specified, the OCSP request is not signed. | 2128 | If neither option is specified, the OCSP request is not signed. |
| 2129 | .It Fl timeout Ar seconds | ||
| 2130 | Connection timeout to the OCSP responder in seconds. | ||
| 2112 | .It Fl trust_other | 2131 | .It Fl trust_other |
| 2113 | The certificates specified by the | 2132 | The certificates specified by the |
| 2114 | .Fl verify_other | 2133 | .Fl verify_other |
| @@ -2160,6 +2179,8 @@ The options for the OCSP server are as follows: | |||
| 2160 | .It Fl CA Ar file | 2179 | .It Fl CA Ar file |
| 2161 | CA certificate corresponding to the revocation information in | 2180 | CA certificate corresponding to the revocation information in |
| 2162 | .Ar indexfile . | 2181 | .Ar indexfile . |
| 2182 | .It Fl ignore_err | ||
| 2183 | Ignore the invalid response. | ||
| 2163 | .It Fl index Ar indexfile | 2184 | .It Fl index Ar indexfile |
| 2164 | .Ar indexfile | 2185 | .Ar indexfile |
| 2165 | is a text index file in ca format | 2186 | is a text index file in ca format |
| @@ -2656,7 +2677,7 @@ With | |||
| 2656 | .Fl password | 2677 | .Fl password |
| 2657 | is equivalent to | 2678 | is equivalent to |
| 2658 | .Fl passout . | 2679 | .Fl passout . |
| 2659 | Otherwise, | 2680 | Otherwise, |
| 2660 | .Fl password | 2681 | .Fl password |
| 2661 | is equivalent to | 2682 | is equivalent to |
| 2662 | .Fl passin . | 2683 | .Fl passin . |
| @@ -3411,15 +3432,18 @@ Any additional fields will be treated as though they were a | |||
| 3411 | .Op Fl aes128 | aes192 | aes256 | des | des3 | 3432 | .Op Fl aes128 | aes192 | aes256 | des | des3 |
| 3412 | .Op Fl check | 3433 | .Op Fl check |
| 3413 | .Op Fl in Ar file | 3434 | .Op Fl in Ar file |
| 3414 | .Op Fl inform Cm der | net | pem | 3435 | .Op Fl inform Cm der | net | pem | pvk |
| 3415 | .Op Fl modulus | 3436 | .Op Fl modulus |
| 3416 | .Op Fl noout | 3437 | .Op Fl noout |
| 3417 | .Op Fl out Ar file | 3438 | .Op Fl out Ar file |
| 3418 | .Op Fl outform Cm der | net | pem | 3439 | .Op Fl outform Cm der | net | pem | pvk |
| 3419 | .Op Fl passin Ar arg | 3440 | .Op Fl passin Ar arg |
| 3420 | .Op Fl passout Ar arg | 3441 | .Op Fl passout Ar arg |
| 3421 | .Op Fl pubin | 3442 | .Op Fl pubin |
| 3422 | .Op Fl pubout | 3443 | .Op Fl pubout |
| 3444 | .Op Fl pvk-none | pvk-strong | pvk-weak | ||
| 3445 | .Op Fl RSAPublicKey_in | ||
| 3446 | .Op Fl RSAPublicKey_out | ||
| 3423 | .Op Fl sgckey | 3447 | .Op Fl sgckey |
| 3424 | .Op Fl text | 3448 | .Op Fl text |
| 3425 | .nr nS 0 | 3449 | .nr nS 0 |
| @@ -3455,7 +3479,7 @@ Check the consistency of an RSA private key. | |||
| 3455 | The input file to read from, | 3479 | The input file to read from, |
| 3456 | or standard input if not specified. | 3480 | or standard input if not specified. |
| 3457 | If the key is encrypted, a pass phrase will be prompted for. | 3481 | If the key is encrypted, a pass phrase will be prompted for. |
| 3458 | .It Fl inform Cm der | net | pem | 3482 | .It Fl inform Cm der | net | pem | pvk |
| 3459 | The input format. | 3483 | The input format. |
| 3460 | .It Fl noout | 3484 | .It Fl noout |
| 3461 | Do not output the encoded version of the key. | 3485 | Do not output the encoded version of the key. |
| @@ -3464,7 +3488,7 @@ Print the value of the modulus of the key. | |||
| 3464 | .It Fl out Ar file | 3488 | .It Fl out Ar file |
| 3465 | The output file to write to, | 3489 | The output file to write to, |
| 3466 | or standard output if not specified. | 3490 | or standard output if not specified. |
| 3467 | .It Fl outform Cm der | net | pem | 3491 | .It Fl outform Cm der | net | pem | pvk |
| 3468 | The output format. | 3492 | The output format. |
| 3469 | .It Fl passin Ar arg | 3493 | .It Fl passin Ar arg |
| 3470 | The key password source. | 3494 | The key password source. |
| @@ -3477,6 +3501,20 @@ not a private key. | |||
| 3477 | Output a public key, | 3501 | Output a public key, |
| 3478 | not a private key. | 3502 | not a private key. |
| 3479 | Automatically set if the input is a public key. | 3503 | Automatically set if the input is a public key. |
| 3504 | .It Xo | ||
| 3505 | .Fl pvk-none | pvk-strong | pvk-weak | ||
| 3506 | .Xc | ||
| 3507 | Enable or disable PVK encoding. | ||
| 3508 | The default is | ||
| 3509 | .Fl pvk-strong . | ||
| 3510 | .It Fl RSAPublicKey_in , RSAPublicKey_out | ||
| 3511 | Same as | ||
| 3512 | .Fl pubin | ||
| 3513 | and | ||
| 3514 | .Fl pubout | ||
| 3515 | except | ||
| 3516 | .Cm RSAPublicKey | ||
| 3517 | format is used instead. | ||
| 3480 | .It Fl sgckey | 3518 | .It Fl sgckey |
| 3481 | Use the modified NET algorithm used with some versions of Microsoft IIS | 3519 | Use the modified NET algorithm used with some versions of Microsoft IIS |
| 3482 | and SGC keys. | 3520 | and SGC keys. |
| @@ -4243,6 +4281,7 @@ debugging purposes. | |||
| 4243 | .Op Fl noindef | 4281 | .Op Fl noindef |
| 4244 | .Op Fl nointern | 4282 | .Op Fl nointern |
| 4245 | .Op Fl nosigs | 4283 | .Op Fl nosigs |
| 4284 | .Op Fl nosmimecap | ||
| 4246 | .Op Fl noverify | 4285 | .Op Fl noverify |
| 4247 | .Op Fl out Ar file | 4286 | .Op Fl out Ar file |
| 4248 | .Op Fl outform Cm der | pem | smime | 4287 | .Op Fl outform Cm der | pem | smime |
| @@ -4440,6 +4479,9 @@ Only use certificates specified in the | |||
| 4440 | The supplied certificates can still be used as untrusted CAs. | 4479 | The supplied certificates can still be used as untrusted CAs. |
| 4441 | .It Fl nosigs | 4480 | .It Fl nosigs |
| 4442 | Do not try to verify the signatures on the message. | 4481 | Do not try to verify the signatures on the message. |
| 4482 | .It Fl nosmimecap | ||
| 4483 | Exclude the list of supported algorithms from signed attributes, | ||
| 4484 | other options such as signing time and content type are still included. | ||
| 4443 | .It Fl noverify | 4485 | .It Fl noverify |
| 4444 | Do not verify the signer's certificate of a signed message. | 4486 | Do not verify the signer's certificate of a signed message. |
| 4445 | .It Fl out Ar file | 4487 | .It Fl out Ar file |
| @@ -6035,6 +6077,8 @@ Insecure legacy format. | |||
| 6035 | .It Cm pem | 6077 | .It Cm pem |
| 6036 | Privacy Enhanced Mail (PEM) | 6078 | Privacy Enhanced Mail (PEM) |
| 6037 | is base64-encoded. | 6079 | is base64-encoded. |
| 6080 | .It Cm pvk | ||
| 6081 | Private Key format. | ||
| 6038 | .It Cm smime | 6082 | .It Cm smime |
| 6039 | An SMIME format message. | 6083 | An SMIME format message. |
| 6040 | .It Cm txt | 6084 | .It Cm txt |
