DOC: ssl: add "allow-0rtt" and "ciphersuites" in crt-list

Support for "allow-0rtt" and "ciphersuites" exists for crt-list.

Fix issue #721.

Should be backported as far as 1.8.
This commit is contained in:
William Lallemand 2020-06-30 16:11:36 +02:00
parent daf8aa62a8
commit 5d03639ba6

View File

@ -12301,10 +12301,11 @@ crt-list <file>
<crtfile> [\[<sslbindconf> ...\]] [[!]<snifilter> ...] <crtfile> [\[<sslbindconf> ...\]] [[!]<snifilter> ...]
sslbindconf support "npn", "alpn", "verify", "ca-file", "ca-verify-file", sslbindconf supports "allow-0rtt", "alpn", "ca-file", "ca-verify-file",
"no-ca-names", "crl-file", "ecdhe", "curves", "ciphers" configuration. With "ciphers", "ciphersuites", "crl-file", "curves", "ecdhe", "no-ca-names",
BoringSSL and Openssl >= 1.1.1 "ssl-min-ver" and "ssl-max-ver" are also "npn", "verify" configuration. With BoringSSL and Openssl >= 1.1.1
supported. It override the configuration set in bind line for the certificate. "ssl-min-ver" and "ssl-max-ver" are also supported. It overrides the
configuration set in bind line for the certificate.
Wildcards are supported in the SNI filter. Negative filter are also supported, Wildcards are supported in the SNI filter. Negative filter are also supported,
only useful in combination with a wildcard filter to exclude a particular SNI. only useful in combination with a wildcard filter to exclude a particular SNI.