]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
DOC: ssl: add "allow-0rtt" and "ciphersuites" in crt-list
authorWilliam Lallemand <wlallemand@haproxy.org>
Tue, 30 Jun 2020 14:11:36 +0000 (16:11 +0200)
committerWilliam Lallemand <wlallemand@haproxy.org>
Tue, 30 Jun 2020 14:15:44 +0000 (16:15 +0200)
Support for "allow-0rtt" and "ciphersuites" exists for crt-list.

Fix issue #721.

Should be backported as far as 1.8.

doc/configuration.txt

index f03620efbce142870b846c7332899c1aaf39ce5d..2aed84ecc863f7d12dd8c49eb25e7cb376641088 100644 (file)
@@ -12301,10 +12301,11 @@ crt-list <file>
 
         <crtfile> [\[<sslbindconf> ...\]] [[!]<snifilter> ...]
 
-  sslbindconf support "npn", "alpn", "verify", "ca-file", "ca-verify-file",
-  "no-ca-names", "crl-file", "ecdhe", "curves", "ciphers" configuration. With
-  BoringSSL and Openssl >= 1.1.1 "ssl-min-ver" and "ssl-max-ver" are also
-  supported. It override the configuration set in bind line for the certificate.
+  sslbindconf supports "allow-0rtt", "alpn", "ca-file", "ca-verify-file",
+  "ciphers", "ciphersuites", "crl-file", "curves", "ecdhe", "no-ca-names",
+  "npn", "verify" configuration. With BoringSSL and Openssl >= 1.1.1
+  "ssl-min-ver" and "ssl-max-ver" are also supported. It overrides the
+  configuration set in bind line for the certificate.
 
   Wildcards are supported in the SNI filter. Negative filter are also supported,
   only useful in combination with a wildcard filter to exclude a particular SNI.