Skip to content
Snippets Groups Projects
Commit 056bd0ac authored by Ben Jencks's avatar Ben Jencks Committed by Howard Chu
Browse files

ITS#7506 DHParamFile: Update docs

Update docs to reflect changes in handling and fix some errors.
parent cfeb2841
No related branches found
No related tags found
No related merge requests found
......@@ -188,18 +188,20 @@ and it doesn't need very much data to work.
This directive is ignored with GnuTLS and Mozilla NSS.
H4: TLSEphemeralDHParamFile <filename>
H4: TLSDHParamFile <filename>
This directive specifies the file that contains parameters for
Diffie-Hellman ephemeral key exchange. This is required in order
to use a DSA certificate on the server side (i.e.
{{EX:TLSCertificateKeyFile}} points to a DSA key). Multiple sets
of parameters can be included in the file; all of them will be
processed. Parameters can be generated using the following command
to use DHE-based cipher suites, including all DSA-based suites (i.e.
{{EX:TLSCertificateKeyFile}} points to a DSA key), and RSA when the 'key
encipherment' key usage is not specified in the certificate. Parameters can be
generated using the following command
> openssl dhparam [-dsaparam] -out <filename> <numbits>
or
> certtool --generate-dh-params --bits <numbits> --outfile <filename>
This directive is ignored with GnuTLS and Mozilla NSS.
This directive is ignored with Mozilla NSS.
H4: TLSVerifyClient { never | allow | try | demand }
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment