summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorschwarze <>2018-02-27 17:35:05 +0000
committerschwarze <>2018-02-27 17:35:05 +0000
commitc2a4b3cc2d9f73d481864b1d74bd0c426c765ca6 (patch)
tree78de5bc8f748be93ae4082fd41f203e8cf6f28d0 /src
parent3fb6affa96233bd790805144d8a6a20c961a68e8 (diff)
downloadopenbsd-c2a4b3cc2d9f73d481864b1d74bd0c426c765ca6.tar.gz
openbsd-c2a4b3cc2d9f73d481864b1d74bd0c426c765ca6.tar.bz2
openbsd-c2a4b3cc2d9f73d481864b1d74bd0c426c765ca6.zip
Add four options that exist in our tree and are documented in OpenSSL.
Diffstat (limited to 'src')
-rw-r--r--src/lib/libssl/man/SSL_CTX_set_options.310
1 files changed, 9 insertions, 1 deletions
diff --git a/src/lib/libssl/man/SSL_CTX_set_options.3 b/src/lib/libssl/man/SSL_CTX_set_options.3
index 453ffdcdf3..0e71083827 100644
--- a/src/lib/libssl/man/SSL_CTX_set_options.3
+++ b/src/lib/libssl/man/SSL_CTX_set_options.3
@@ -1,4 +1,4 @@
1.\" $OpenBSD: SSL_CTX_set_options.3,v 1.6 2018/02/27 17:17:00 schwarze Exp $ 1.\" $OpenBSD: SSL_CTX_set_options.3,v 1.7 2018/02/27 17:35:05 schwarze Exp $
2.\" full merge up to: OpenSSL 7946ab33 Dec 6 17:56:41 2015 +0100 2.\" full merge up to: OpenSSL 7946ab33 Dec 6 17:56:41 2015 +0100
3.\" selective merge up to: OpenSSL edb79c3a Mar 29 10:07:14 2017 +1000 3.\" selective merge up to: OpenSSL edb79c3a Mar 29 10:07:14 2017 +1000
4.\" 4.\"
@@ -174,6 +174,9 @@ When choosing a cipher, use the server's preferences instead of the client
174preferences. 174preferences.
175When not set, the server will always follow the client's preferences. 175When not set, the server will always follow the client's preferences.
176When set, the server will choose following its own preferences. 176When set, the server will choose following its own preferences.
177.It Dv SSL_OP_COOKIE_EXCHANGE
178Turn on Cookie Exchange as described in RFC4347 Section 4.2.1.
179Only affects DTLS connections.
177.It Dv SSL_OP_LEGACY_SERVER_CONNECT 180.It Dv SSL_OP_LEGACY_SERVER_CONNECT
178Allow legacy insecure renegotiation between OpenSSL and unpatched servers 181Allow legacy insecure renegotiation between OpenSSL and unpatched servers
179.Em only : 182.Em only :
@@ -181,6 +184,9 @@ this option is currently set by default.
181See the 184See the
182.Sx SECURE RENEGOTIATION 185.Sx SECURE RENEGOTIATION
183section for more details. 186section for more details.
187.It Dv SSL_OP_NO_QUERY_MTU
188Do not query the MTU.
189Only affects DTLS connections.
184.It Dv SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION 190.It Dv SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION
185When performing renegotiation as a server, always start a new session (i.e., 191When performing renegotiation as a server, always start a new session (i.e.,
186session resumption requests are only accepted in the initial handshake). 192session resumption requests are only accepted in the initial handshake).
@@ -226,12 +232,14 @@ and no longer have any effect:
226.Dv SSL_OP_NETSCAPE_CHALLENGE_BUG , 232.Dv SSL_OP_NETSCAPE_CHALLENGE_BUG ,
227.Dv SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG , 233.Dv SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG ,
228.Dv SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG , 234.Dv SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG ,
235.Dv SSL_OP_NO_COMPRESSION ,
229.Dv SSL_OP_NO_SSLv2 , 236.Dv SSL_OP_NO_SSLv2 ,
230.Dv SSL_OP_NO_SSLv3 , 237.Dv SSL_OP_NO_SSLv3 ,
231.Dv SSL_OP_PKCS1_CHECK_1 , 238.Dv SSL_OP_PKCS1_CHECK_1 ,
232.Dv SSL_OP_PKCS1_CHECK_2 , 239.Dv SSL_OP_PKCS1_CHECK_2 ,
233.Dv SSL_OP_SAFARI_ECDHE_ECDSA_BUG , 240.Dv SSL_OP_SAFARI_ECDHE_ECDSA_BUG ,
234.Dv SSL_OP_SINGLE_DH_USE , 241.Dv SSL_OP_SINGLE_DH_USE ,
242.Dv SSL_OP_SINGLE_ECDH_USE ,
235.Dv SSL_OP_SSLEAY_080_CLIENT_DH_BUG , 243.Dv SSL_OP_SSLEAY_080_CLIENT_DH_BUG ,
236.Dv SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG , 244.Dv SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG ,
237.Dv SSL_OP_TLS_BLOCK_PADDING_BUG , 245.Dv SSL_OP_TLS_BLOCK_PADDING_BUG ,