]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
DH_check: Emphasize the importance of return value check
authorTomas Mraz <tomas@openssl.org>
Tue, 3 Oct 2023 12:43:13 +0000 (14:43 +0200)
committerTomas Mraz <tomas@openssl.org>
Thu, 5 Oct 2023 09:25:13 +0000 (11:25 +0200)
Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com>
Reviewed-by: Paul Dale <pauli@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/22262)

(cherry picked from commit f7b80136a3df4396b19ebb86d4814d8cefe6d6db)

doc/man3/DH_generate_parameters.pod

index 1098a161ea63f2517fb3fd2f254b9904bd66554d..fa4ac54fb81b7cbc556ced317703be55b1395ec8 100644 (file)
@@ -128,6 +128,10 @@ The parameter B<j> is invalid.
 
 =back
 
+If 0 is returned or B<*codes> is set to a nonzero value the supplied
+parameters should not be used for Diffie-Hellman operations otherwise
+the security properties of the key exchange are not guaranteed.
+
 DH_check_ex(), DH_check_params() and DH_check_pub_key_ex() are similar to
 DH_check() and DH_check_params() respectively, but the error reasons are added
 to the thread's error queue instead of provided as return values from the