X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=lib%2Fssl.man;h=5f0215c01fbe866ead5e34cf744b29255287d361;hb=003ce655b7116d18c86a74c50391e54990346931;hp=8e530f45d63ee96854bed4e086cc4953ab78c2d1;hpb=a4af00400a835eb87569ba40e21874c05e872c0f;p=sliver-openvswitch.git diff --git a/lib/ssl.man b/lib/ssl.man index 8e530f45d..5f0215c01 100644 --- a/lib/ssl.man +++ b/lib/ssl.man @@ -1,20 +1,30 @@ -.SS "Public Key Infrastructure Options" +.de IQ +. br +. ns +. IP "\\$1" +.. .IP "\fB\-p\fR \fIprivkey.pem\fR" .IQ "\fB\-\-private\-key=\fIprivkey.pem\fR" Specifies a PEM file containing the private key used as \fB\*(PN\fR's identity for outgoing SSL connections. - +. .IP "\fB\-c\fR \fIcert.pem\fR" .IQ "\fB\-\-certificate=\fIcert.pem\fR" Specifies a PEM file containing a certificate that certifies the private key specified on \fB\-p\fR or \fB\-\-private\-key\fR to be trustworthy. The certificate must be signed by the certificate authority (CA) that the peer in SSL connections will use to verify it. - -.IP "\fB\-C\fR \fIswitch\-cacert.pem\fR" -.IQ "\fB\-\-ca\-cert=\fIswitch\-cacert.pem\fR" +. +.IP "\fB\-C\fR \fIcacert.pem\fR" +.IQ "\fB\-\-ca\-cert=\fIcacert.pem\fR" Specifies a PEM file containing the CA certificate that \fB\*(PN\fR should use to verify certificates presented to it by SSL peers. (This may be the same certificate that SSL peers use to verify the certificate specified on \fB\-c\fR or \fB\-\-certificate\fR, or it may -beq a different one, depending on the PKI design in use.) +be a different one, depending on the PKI design in use.) +. +.IP "\fB\-C none\fR" +.IQ "\fB\-\-ca\-cert=none\fR" +Disables verification of certificates presented by SSL peers. This +introduces a security risk, because it means that certificates cannot +be verified to be those of known trusted hosts.