X-Git-Url: http://git.onelab.eu/?a=blobdiff_plain;f=lib%2Fssl.man;h=5f0215c01fbe866ead5e34cf744b29255287d361;hb=4e8e4213a815a30216e855a805a8bcd5b8c5a886;hp=30c25c9e0bb58932236ba33aa03a2b358e433d54;hpb=1af5bea7f37f74acd9aca5d8f2f15344c8c127dc;p=sliver-openvswitch.git diff --git a/lib/ssl.man b/lib/ssl.man index 30c25c9e0..5f0215c01 100644 --- a/lib/ssl.man +++ b/lib/ssl.man @@ -1,4 +1,8 @@ -.SS "Public Key Infrastructure Options" +.de IQ +. br +. ns +. IP "\\$1" +.. .IP "\fB\-p\fR \fIprivkey.pem\fR" .IQ "\fB\-\-private\-key=\fIprivkey.pem\fR" Specifies a PEM file containing the private key used as \fB\*(PN\fR's @@ -18,3 +22,9 @@ should use to verify certificates presented to it by SSL peers. (This may be the same certificate that SSL peers use to verify the certificate specified on \fB\-c\fR or \fB\-\-certificate\fR, or it may be a different one, depending on the PKI design in use.) +. +.IP "\fB\-C none\fR" +.IQ "\fB\-\-ca\-cert=none\fR" +Disables verification of certificates presented by SSL peers. This +introduces a security risk, because it means that certificates cannot +be verified to be those of known trusted hosts.