mirror of
https://git.haproxy.org/git/haproxy.git/
synced 2025-09-22 06:11:32 +02:00
DOC: ssl: add "allow-0rtt" and "ciphersuites" in crt-list
Support for "allow-0rtt" and "ciphersuites" exists for crt-list. Fix issue #721. Should be backported as far as 1.8.
This commit is contained in:
parent
daf8aa62a8
commit
5d03639ba6
@ -12301,10 +12301,11 @@ crt-list <file>
|
|||||||
|
|
||||||
<crtfile> [\[<sslbindconf> ...\]] [[!]<snifilter> ...]
|
<crtfile> [\[<sslbindconf> ...\]] [[!]<snifilter> ...]
|
||||||
|
|
||||||
sslbindconf support "npn", "alpn", "verify", "ca-file", "ca-verify-file",
|
sslbindconf supports "allow-0rtt", "alpn", "ca-file", "ca-verify-file",
|
||||||
"no-ca-names", "crl-file", "ecdhe", "curves", "ciphers" configuration. With
|
"ciphers", "ciphersuites", "crl-file", "curves", "ecdhe", "no-ca-names",
|
||||||
BoringSSL and Openssl >= 1.1.1 "ssl-min-ver" and "ssl-max-ver" are also
|
"npn", "verify" configuration. With BoringSSL and Openssl >= 1.1.1
|
||||||
supported. It override the configuration set in bind line for the certificate.
|
"ssl-min-ver" and "ssl-max-ver" are also supported. It overrides the
|
||||||
|
configuration set in bind line for the certificate.
|
||||||
|
|
||||||
Wildcards are supported in the SNI filter. Negative filter are also supported,
|
Wildcards are supported in the SNI filter. Negative filter are also supported,
|
||||||
only useful in combination with a wildcard filter to exclude a particular SNI.
|
only useful in combination with a wildcard filter to exclude a particular SNI.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user