summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoel Sing <jsing@cvs.openbsd.org>2013-07-18 12:39:18 +0000
committerJoel Sing <jsing@cvs.openbsd.org>2013-07-18 12:39:18 +0000
commit282de90e82121bc324891aba717c90857e61d4ad (patch)
tree861ef67dfa177599ead84e08b322c9cc64b5945a
parent36697312deef3a478248f46055b72f47517ddea9 (diff)
Document SSLECDHCurve.
ok jmc@
-rw-r--r--usr.sbin/httpd/htdocs/manual/mod/mod_ssl/ssl_reference.html67
1 files changed, 63 insertions, 4 deletions
diff --git a/usr.sbin/httpd/htdocs/manual/mod/mod_ssl/ssl_reference.html b/usr.sbin/httpd/htdocs/manual/mod/mod_ssl/ssl_reference.html
index a744d9813e6..3ea020662e9 100644
--- a/usr.sbin/httpd/htdocs/manual/mod/mod_ssl/ssl_reference.html
+++ b/usr.sbin/httpd/htdocs/manual/mod/mod_ssl/ssl_reference.html
@@ -294,7 +294,8 @@ virtual host''), which can occur inside the server config files both outside
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC7"><strong>SSLEngine</strong></a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC8"><strong>SSLProtocol</strong></a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC9"><strong>SSLCipherSuite</strong></a><br>
-&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC9a"><strong>SSLHonorCipherOrder</strong></a><br>
+&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC9a"><strong>SSLECDHCurve</strong></a><br>
+&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC9b"><strong>SSLHonorCipherOrder</strong></a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC10"><strong>SSLCertificateFile</strong></a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC11"><strong>SSLCertificateKeyFile</strong></a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href="#ToC12"><strong>SSLCertificateChainFile</strong></a><br>
@@ -1213,11 +1214,69 @@ SSLCipherSuite RSA:!EXP:!NULL:+HIGH:+MEDIUM:-LOW
</tr></table>
</td></tr></table>
</div>
+<!-- SSLECDHCurve --------------------------------------------->
+<p>
+<br>
+<a name="SSLECDHCurve"></a>
+<h2><a name="ToC9a">SSLECDHCurve</a></h2>
+<table cellspacing="0" cellpadding="1" bgcolor="#cccccc" border="0" summary="">
+<tr>
+<td>
+<table bgcolor="white" width="600" cellspacing="0" cellpadding="5" border="0" summary="">
+<tr>
+<td>
+<table cellspacing="0" cellpadding="1" border="0" summary="">
+<tr><td>
+<font face="Arial,Helvetica"><b>Name:</b></font></a> </td><td> <b>SSLECDHCurve</b></td></tr>
+<tr><td>
+<font face="Arial,Helvetica"><b>Description:</b></font></a> </td><td> Named curve to use for ephemeral EC keys
+</td></tr>
+<tr><td><a
+ href="../directive-dict.html#Syntax"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Syntax:</b></font></a> </td><td> <code>SSLECDHCurve</code> <em>curve</em></td></tr>
+<tr><td><a
+ href="../directive-dict.html#Default"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Default:</b></font></a> </td><td> <code>prime256v1</code></td></tr>
+<tr><td><a
+ href="../directive-dict.html#Context"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Context:</b></font></a> </td><td> server config, virtual host</td></tr>
+<tr><td><a
+ href="../directive-dict.html#Override"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Override:</b></font></a> </td><td> <em>Not applicable</em></td></tr>
+<tr><td><a
+ href="../directive-dict.html#Status"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Status:</b></font></a> </td><td> Extension</td></tr>
+<tr><td><a
+ href="../directive-dict.html#Module"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Module:</b></font></a> </td><td> mod_ssl</td></tr>
+<tr><td><a
+ href="../directive-dict.html#Compatibility"
+ rel="Help"
+><font face="Arial,Helvetica"><b>Compatibility:</b></font></a> </td><td></td></tr>
+</table>
+</td>
+</tr>
+</table>
+</td>
+</tr>
+</table>
+<p>
+This option specifies the named curve to use when generating ephemeral EC keys
+for an ECDHE-based cipher suite. Any named curve known by OpenSSL may be
+specified. Setting this to <code>none</code> results in no named curve being
+configured for ECDH, effectively disabling ECDHE-based cipher suites.
+<p>
<!-- SSLHonorCipherOrder --------------------------------------------->
<p>
<br>
-<a name="SSLCertificateFile"></a>
-<h2><a name="ToC9a">SSLHonorCipherOrder</a></h2>
+<a name="SSLHonorCipherOrder"></a>
+<h2><a name="ToC9b">SSLHonorCipherOrder</a></h2>
<table cellspacing="0" cellpadding="1" bgcolor="#cccccc" border="0" summary="">
<tr>
<td>
@@ -1236,7 +1295,7 @@ SSLCipherSuite RSA:!EXP:!NULL:+HIGH:+MEDIUM:-LOW
<tr><td><a
href="../directive-dict.html#Default"
rel="Help"
-><font face="Arial,Helvetica"><b>Default:</b></font></a> </td><td> <code>HonorCip Off</td></tr>
+><font face="Arial,Helvetica"><b>Default:</b></font></a> </td><td> <code>Off</code></td></tr>
<tr><td><a
href="../directive-dict.html#Context"
rel="Help"