From: Tomas Mraz Date: Tue, 2 Apr 2024 16:47:26 +0000 (+0200) Subject: openssl-crl(1): The -verify option is implied by -CA* options X-Git-Url: http://git.ipfire.org/?p=thirdparty%2Fopenssl.git;a=commitdiff_plain;h=a16f2e7651b22ee992bb0c279e25164b519c1e80 openssl-crl(1): The -verify option is implied by -CA* options Reviewed-by: Dmitry Belyavskiy Reviewed-by: Todd Short (Merged from https://github.com/openssl/openssl/pull/24024) --- diff --git a/doc/man1/openssl-crl.pod.in b/doc/man1/openssl-crl.pod.in index 630c15dab5..cbc8c044c7 100644 --- a/doc/man1/openssl-crl.pod.in +++ b/doc/man1/openssl-crl.pod.in @@ -97,6 +97,9 @@ Verify the signature in the CRL. If the verification fails, the program will immediately exit, i.e. further option processing (e.g. B<-gendelta>) is skipped. +This option is implicitly enabled if any of B<-CApath>, B<-CAfile> +or B<-CAstore> is specified. + =item B<-noout> Don't output the encoded version of the CRL.