2000-01-09 09:26:43 +08:00
|
|
|
=pod
|
2019-10-31 11:35:08 +08:00
|
|
|
{- OpenSSL::safe::output_do_not_edit_headers(); -}
|
2019-10-13 05:45:56 +08:00
|
|
|
|
2000-01-09 09:26:43 +08:00
|
|
|
=head1 NAME
|
|
|
|
|
2019-08-22 07:04:41 +08:00
|
|
|
openssl-s_server - SSL/TLS server program
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
|
2000-10-24 03:13:35 +08:00
|
|
|
B<openssl> B<s_server>
|
2016-02-06 00:58:45 +08:00
|
|
|
[B<-help>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-port> I<+int>]
|
|
|
|
[B<-accept> I<val>]
|
|
|
|
[B<-unix> I<val>]
|
2016-11-13 04:08:32 +08:00
|
|
|
[B<-4>]
|
|
|
|
[B<-6>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-unlink>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-context> I<val>]
|
|
|
|
[B<-verify> I<int>]
|
|
|
|
[B<-Verify> I<int>]
|
|
|
|
[B<-cert> I<infile>]
|
|
|
|
[B<-naccept> I<+int>]
|
|
|
|
[B<-serverinfo> I<val>]
|
|
|
|
[B<-certform> B<DER>|B<PEM>]
|
|
|
|
[B<-key> I<infile>]
|
2019-10-10 09:48:33 +08:00
|
|
|
[B<-keyform> B<DER>|B<PEM>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-pass> I<val>]
|
|
|
|
[B<-dcert> I<infile>]
|
|
|
|
[B<-dcertform> B<DER>|B<PEM>]
|
|
|
|
[B<-dkey> I<infile>]
|
|
|
|
[B<-dkeyform> B<DER>|B<PEM>]
|
|
|
|
[B<-dpass> I<val>]
|
2000-01-09 09:26:43 +08:00
|
|
|
[B<-nbio_test>]
|
|
|
|
[B<-crlf>]
|
|
|
|
[B<-debug>]
|
2001-11-10 10:12:09 +08:00
|
|
|
[B<-msg>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-msgfile> I<outfile>]
|
2000-01-09 09:26:43 +08:00
|
|
|
[B<-state>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-nocert>]
|
|
|
|
[B<-quiet>]
|
|
|
|
[B<-no_resume_ephemeral>]
|
|
|
|
[B<-www>]
|
|
|
|
[B<-WWW>]
|
|
|
|
[B<-servername>]
|
|
|
|
[B<-servername_fatal>]
|
2019-10-02 23:13:03 +08:00
|
|
|
[B<-cert2> I<infile>]
|
|
|
|
[B<-key2> I<infile>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-tlsextdebug>]
|
|
|
|
[B<-HTTP>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-id_prefix> I<val>]
|
|
|
|
[B<-keymatexport> I<val>]
|
|
|
|
[B<-keymatexportlen> I<+int>]
|
|
|
|
[B<-CRL> I<infile>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-crl_download>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-cert_chain> I<infile>]
|
|
|
|
[B<-dcert_chain> I<infile>]
|
|
|
|
[B<-chainCApath> I<dir>]
|
|
|
|
[B<-verifyCApath> I<dir>]
|
2019-03-07 22:26:34 +08:00
|
|
|
[B<-chainCAstore> I<uri>]
|
|
|
|
[B<-verifyCAstore> I<uri>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-no_cache>]
|
|
|
|
[B<-ext_cache>]
|
|
|
|
[B<-verify_return_error>]
|
|
|
|
[B<-verify_quiet>]
|
|
|
|
[B<-build_chain>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-chainCAfile> I<infile>]
|
|
|
|
[B<-verifyCAfile> I<infile>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-ign_eof>]
|
|
|
|
[B<-no_ign_eof>]
|
|
|
|
[B<-status>]
|
|
|
|
[B<-status_verbose>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-status_timeout> I<int>]
|
|
|
|
[B<-status_url> I<val>]
|
|
|
|
[B<-status_file> I<infile>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-trace>]
|
|
|
|
[B<-security_debug>]
|
|
|
|
[B<-security_debug_verbose>]
|
|
|
|
[B<-brief>]
|
|
|
|
[B<-rev>]
|
|
|
|
[B<-async>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-ssl_config> I<val>]
|
|
|
|
[B<-max_send_frag> I<+int>]
|
|
|
|
[B<-split_send_frag> I<+int>]
|
|
|
|
[B<-max_pipelines> I<+int>]
|
|
|
|
[B<-read_buf> I<+int>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-no_ssl3>]
|
|
|
|
[B<-no_tls1>]
|
|
|
|
[B<-no_tls1_1>]
|
|
|
|
[B<-no_tls1_2>]
|
|
|
|
[B<-no_tls1_3>]
|
|
|
|
[B<-bugs>]
|
|
|
|
[B<-no_comp>]
|
|
|
|
[B<-comp>]
|
|
|
|
[B<-no_ticket>]
|
2018-12-04 20:31:17 +08:00
|
|
|
[B<-num_tickets>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-serverpref>]
|
|
|
|
[B<-legacy_renegotiation>]
|
|
|
|
[B<-no_renegotiation>]
|
|
|
|
[B<-legacy_server_connect>]
|
|
|
|
[B<-no_resumption_on_reneg>]
|
|
|
|
[B<-no_legacy_server_connect>]
|
2017-07-03 22:59:30 +08:00
|
|
|
[B<-allow_no_dhe_kex>]
|
2015-12-22 04:19:29 +08:00
|
|
|
[B<-prioritize_chacha>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-strict>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-sigalgs> I<val>]
|
|
|
|
[B<-client_sigalgs> I<val>]
|
|
|
|
[B<-groups> I<val>]
|
|
|
|
[B<-curves> I<val>]
|
|
|
|
[B<-named_curve> I<val>]
|
|
|
|
[B<-cipher> I<val>]
|
|
|
|
[B<-ciphersuites> I<val>]
|
|
|
|
[B<-dhparam> I<infile>]
|
|
|
|
[B<-record_padding> I<val>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-debug_broken_protocol>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-policy> I<val>]
|
|
|
|
[B<-purpose> I<val>]
|
|
|
|
[B<-verify_name> I<val>]
|
|
|
|
[B<-verify_depth> I<int>]
|
|
|
|
[B<-auth_level> I<int>]
|
|
|
|
[B<-attime> I<intmax>]
|
|
|
|
[B<-verify_hostname> I<val>]
|
|
|
|
[B<-verify_email> I<val>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-verify_ip>]
|
2014-06-19 21:34:49 +08:00
|
|
|
[B<-ignore_critical>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-issuer_checks>]
|
|
|
|
[B<-crl_check>]
|
|
|
|
[B<-crl_check_all>]
|
|
|
|
[B<-policy_check>]
|
|
|
|
[B<-explicit_policy>]
|
2014-06-19 21:34:49 +08:00
|
|
|
[B<-inhibit_any>]
|
|
|
|
[B<-inhibit_map>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-x509_strict>]
|
|
|
|
[B<-extended_crl>]
|
|
|
|
[B<-use_deltas>]
|
2014-06-19 21:34:49 +08:00
|
|
|
[B<-policy_print>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-check_ss_sig>]
|
|
|
|
[B<-trusted_first>]
|
2014-06-19 21:34:49 +08:00
|
|
|
[B<-suiteB_128_only>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-suiteB_128>]
|
2014-06-19 21:34:49 +08:00
|
|
|
[B<-suiteB_192>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-partial_chain>]
|
2015-01-27 19:15:15 +08:00
|
|
|
[B<-no_alt_chains>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-no_check_time>]
|
|
|
|
[B<-allow_proxy_certs>]
|
|
|
|
[B<-nbio>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-psk_identity> I<val>]
|
|
|
|
[B<-psk_hint> I<val>]
|
|
|
|
[B<-psk> I<val>]
|
|
|
|
[B<-psk_session> I<file>]
|
|
|
|
[B<-srpvfile> I<infile>]
|
|
|
|
[B<-srpuserseed> I<val>]
|
2000-01-09 09:26:43 +08:00
|
|
|
[B<-ssl3>]
|
|
|
|
[B<-tls1>]
|
2016-10-22 00:39:33 +08:00
|
|
|
[B<-tls1_1>]
|
|
|
|
[B<-tls1_2>]
|
|
|
|
[B<-tls1_3>]
|
2015-04-10 20:10:05 +08:00
|
|
|
[B<-dtls>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-timeout>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-mtu> I<+int>]
|
2017-06-07 18:43:03 +08:00
|
|
|
[B<-listen>]
|
2015-04-10 20:10:05 +08:00
|
|
|
[B<-dtls1>]
|
|
|
|
[B<-dtls1_2>]
|
2017-04-25 21:37:25 +08:00
|
|
|
[B<-sctp>]
|
2018-12-26 19:44:53 +08:00
|
|
|
[B<-sctp_label_bug>]
|
2000-01-09 09:26:43 +08:00
|
|
|
[B<-no_dhe>]
|
2019-09-26 03:20:11 +08:00
|
|
|
[B<-nextprotoneg> I<val>]
|
|
|
|
[B<-use_srtp> I<val>]
|
|
|
|
[B<-alpn> I<val>]
|
|
|
|
[B<-keylogfile> I<outfile>]
|
|
|
|
[B<-max_early_data> I<int>]
|
2017-02-25 00:17:00 +08:00
|
|
|
[B<-early_data>]
|
2018-06-15 21:55:06 +08:00
|
|
|
[B<-anti_replay>]
|
|
|
|
[B<-no_anti_replay>]
|
2019-05-09 07:16:19 +08:00
|
|
|
[B<-http_server_binmode>]
|
2019-10-25 11:02:09 +08:00
|
|
|
{- $OpenSSL::safe::opt_name_synopsis -}
|
2019-10-13 05:45:56 +08:00
|
|
|
{- $OpenSSL::safe::opt_x_synopsis -}
|
|
|
|
{- $OpenSSL::safe::opt_trust_synopsis -}
|
|
|
|
{- $OpenSSL::safe::opt_r_synopsis -}
|
2019-10-13 05:45:56 +08:00
|
|
|
{- $OpenSSL::safe::opt_engine_synopsis -}
|
2014-06-06 22:48:43 +08:00
|
|
|
|
2019-10-11 23:52:12 +08:00
|
|
|
=for openssl ifdef unix 4 6 unlink no_dhe nextprotoneg use_srtp engine
|
2019-09-23 07:49:25 +08:00
|
|
|
|
2019-10-11 23:52:12 +08:00
|
|
|
=for openssl ifdef status status_verbose status_timeout status_url status_file
|
2019-09-23 07:49:25 +08:00
|
|
|
|
2019-10-11 23:52:12 +08:00
|
|
|
=for openssl ifdef psk_hint srpvfile srpuserseed sctp sctp_label_bug
|
2019-09-23 07:49:25 +08:00
|
|
|
|
2019-10-11 23:52:12 +08:00
|
|
|
=for openssl ifdef sctp sctp_label_bug trace mtu timeout listen
|
2019-09-23 07:49:25 +08:00
|
|
|
|
2019-10-11 23:52:12 +08:00
|
|
|
=for openssl ifdef ssl3 tls1 tls1_1 tls1_2 tls1_3 dtls mtu dtls1 dtls1_2
|
2019-09-23 07:49:25 +08:00
|
|
|
|
2000-01-09 09:26:43 +08:00
|
|
|
=head1 DESCRIPTION
|
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
This command implements a generic SSL/TLS server which
|
|
|
|
listens for connections on a given port using SSL/TLS.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
=head1 OPTIONS
|
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
In addition to the options below, this command also supports
|
|
|
|
the common and server only options documented
|
2019-10-02 02:06:22 +08:00
|
|
|
L<SSL_CONF_cmd(3)/Supported Command Line Commands>
|
2012-11-20 00:07:53 +08:00
|
|
|
|
2000-01-09 09:26:43 +08:00
|
|
|
=over 4
|
|
|
|
|
2016-02-06 00:58:45 +08:00
|
|
|
=item B<-help>
|
|
|
|
|
|
|
|
Print out a usage message.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-port> I<+int>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2016-02-22 05:37:14 +08:00
|
|
|
The TCP port to listen on for connections. If not specified 4433 is used.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-accept> I<val>
|
2016-11-13 04:08:32 +08:00
|
|
|
|
|
|
|
The optional TCP host and port to listen on for connections. If not specified, *:4433 is used.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-unix> I<val>
|
2016-11-13 04:08:32 +08:00
|
|
|
|
|
|
|
Unix domain socket to accept on.
|
|
|
|
|
|
|
|
=item B<-4>
|
|
|
|
|
|
|
|
Use IPv4 only.
|
|
|
|
|
|
|
|
=item B<-6>
|
|
|
|
|
|
|
|
Use IPv6 only.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-unlink>
|
|
|
|
|
|
|
|
For -unix, unlink any existing socket first.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-context> I<val>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2016-02-22 05:37:14 +08:00
|
|
|
Sets the SSL context id. It can be given any string value. If this option
|
2000-01-22 06:38:52 +08:00
|
|
|
is not present a default value will be used.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-verify> I<int>, B<-Verify> I<int>
|
2017-06-07 18:43:03 +08:00
|
|
|
|
|
|
|
The verify depth to use. This specifies the maximum length of the
|
|
|
|
client certificate chain and makes the server request a certificate from
|
|
|
|
the client. With the B<-verify> option a certificate is requested but the
|
|
|
|
client does not have to send one, with the B<-Verify> option the client
|
|
|
|
must supply a certificate or an error occurs.
|
|
|
|
|
|
|
|
If the cipher suite cannot request a client certificate (for example an
|
|
|
|
anonymous cipher suite or PSK) this option has no effect.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-cert> I<infile>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
The certificate to use, most servers cipher suites require the use of a
|
|
|
|
certificate and some require a certificate with a certain public key type:
|
|
|
|
for example the DSS cipher suites require a certificate containing a DSS
|
2019-10-02 02:19:45 +08:00
|
|
|
(DSA) key. If not specified then the filename F<server.pem> will be used.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2018-05-09 23:30:41 +08:00
|
|
|
=item B<-cert_chain>
|
|
|
|
|
|
|
|
A file containing trusted certificates to use when attempting to build the
|
|
|
|
client/server certificate chain related to the certificate specified via the
|
|
|
|
B<-cert> option.
|
|
|
|
|
|
|
|
=item B<-build_chain>
|
|
|
|
|
|
|
|
Specify whether the application should build the certificate chain to be
|
|
|
|
provided to the client.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-naccept> I<+int>
|
2017-06-07 18:43:03 +08:00
|
|
|
|
|
|
|
The server will exit after receiving the specified number of connections,
|
|
|
|
default unlimited.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-serverinfo> I<val>
|
2017-06-07 18:43:03 +08:00
|
|
|
|
|
|
|
A file containing one or more blocks of PEM data. Each PEM block
|
|
|
|
must encode a TLS ServerHello extension (2 bytes type, 2 bytes length,
|
|
|
|
followed by "length" bytes of extension data). If the client sends
|
|
|
|
an empty TLS ClientHello extension matching the type, the corresponding
|
|
|
|
ServerHello extension will be returned.
|
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
=item B<-certform> B<DER>|B<PEM>, B<-CRLForm> B<DER>|B<PEM>
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
The certificate and CRL format; the default is PEM.
|
|
|
|
See L<openssl(1)/Format Options> for details.
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-key> I<infile>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
The private key to use. If not specified then the certificate file will
|
|
|
|
be used.
|
|
|
|
|
2019-10-13 05:45:56 +08:00
|
|
|
=item B<-keyform> B<DER>|B<PEM>
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
The key format; the default is B<PEM>.
|
|
|
|
See L<openssl(1)/Format Options> for details.
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-pass> I<val>
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
The private key password source.
|
|
|
|
For more information about the format of I<val>,
|
2019-10-09 01:10:04 +08:00
|
|
|
see L<openssl(1)/Pass Phrase Options>.
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-dcert> I<infile>, B<-dkey> I<infile>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2016-02-22 05:37:14 +08:00
|
|
|
Specify an additional certificate and private key, these behave in the
|
2000-01-09 09:26:43 +08:00
|
|
|
same manner as the B<-cert> and B<-key> options except there is no default
|
|
|
|
if they are not specified (no additional certificate and key is used). As
|
|
|
|
noted above some cipher suites require a certificate containing a key of
|
|
|
|
a certain type. Some cipher suites need a certificate carrying an RSA key
|
|
|
|
and some a DSS (DSA) key. By using RSA and DSS certificates and keys
|
|
|
|
a server can support clients which only support RSA or DSS cipher suites
|
|
|
|
by using an appropriate certificate.
|
|
|
|
|
2018-05-09 23:30:41 +08:00
|
|
|
=item B<-dcert_chain>
|
|
|
|
|
|
|
|
A file containing trusted certificates to use when attempting to build the
|
|
|
|
server certificate chain when a certificate specified via the B<-dcert> option
|
|
|
|
is in use.
|
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
=item B<-dcertform> B<DER>|B<PEM>, B<-dkeyform> B<DER>|B<PEM>
|
|
|
|
|
|
|
|
The format of the certificate and private key; the default is B<PEM>
|
|
|
|
see L<openssl(1)/Format Options>.
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2019-10-10 09:48:33 +08:00
|
|
|
=item B<-dpass> I<val>
|
|
|
|
|
|
|
|
The passphrase for the additional private key.
|
|
|
|
For more information about the format of I<val>,
|
|
|
|
see L<openssl(1)/Pass Phrase Options>.
|
2004-11-17 01:30:59 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-nbio_test>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Tests non blocking I/O.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-crlf>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
This option translated a line feed from the terminal into CR+LF.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-debug>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Print extensive debugging information including a hex dump of all traffic.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-msg>
|
2008-05-19 15:52:15 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Show all protocol messages with hex dump.
|
2008-05-19 15:52:15 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-msgfile> I<outfile>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
File to send output of B<-msg> or B<-trace> to, default standard output.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-state>
|
|
|
|
|
|
|
|
Prints the SSL session states.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-chainCApath> I<dir>
|
2018-05-09 23:30:41 +08:00
|
|
|
|
|
|
|
The directory to use for building the chain provided to the client. This
|
2019-10-02 03:57:00 +08:00
|
|
|
directory must be in "hash format", see L<openssl-verify(1)> for more
|
|
|
|
information.
|
2018-05-09 23:30:41 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-chainCAfile> I<file>
|
2018-05-09 23:30:41 +08:00
|
|
|
|
|
|
|
A file containing trusted certificates to use when attempting to build the
|
|
|
|
server certificate chain.
|
|
|
|
|
2019-03-07 22:26:34 +08:00
|
|
|
=item B<-chainCAstore> I<uri>
|
|
|
|
|
|
|
|
The URI to a store to use for building the chain provided to the client.
|
|
|
|
The URI may indicate a single certificate, as well as a collection of
|
|
|
|
them.
|
|
|
|
With URIs in the C<file:> scheme, this acts as B<-chainCAfile> or
|
|
|
|
B<-chainCApath>, depending on if the URI indicates a directory or a
|
|
|
|
single file.
|
|
|
|
See L<ossl_store-file(7)> for more information on the C<file:> scheme.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-nocert>
|
2014-08-28 02:23:39 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
If this option is set then no certificate is used. This restricts the
|
|
|
|
cipher suites available to the anonymous ones (currently just anonymous
|
|
|
|
DH).
|
2014-08-28 02:23:39 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-quiet>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Inhibit printing of session and certificate information.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-www>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Sends a status message back to the client when it connects. This includes
|
|
|
|
information about the ciphers used and various session parameters.
|
|
|
|
The output is in HTML format so this option will normally be used with a
|
2018-09-13 00:11:10 +08:00
|
|
|
web browser. Cannot be used in conjunction with B<-early_data>.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-WWW>
|
2001-11-10 10:12:09 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Emulates a simple web server. Pages will be resolved relative to the
|
|
|
|
current directory, for example if the URL https://myhost/page.html is
|
2019-10-02 02:19:45 +08:00
|
|
|
requested the file F<./page.html> will be loaded. Cannot be used in conjunction
|
2018-09-13 00:11:10 +08:00
|
|
|
with B<-early_data>.
|
2001-11-10 10:12:09 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-tlsextdebug>
|
2012-11-20 00:37:18 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Print a hex dump of any TLS extensions received from the server.
|
2012-11-20 00:37:18 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-HTTP>
|
2012-11-20 00:37:18 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Emulates a simple web server. Pages will be resolved relative to the
|
|
|
|
current directory, for example if the URL https://myhost/page.html is
|
2019-10-02 02:19:45 +08:00
|
|
|
requested the file F<./page.html> will be loaded. The files loaded are
|
2017-06-07 18:43:03 +08:00
|
|
|
assumed to contain a complete and correct HTTP response (lines that
|
2018-09-13 00:11:10 +08:00
|
|
|
are part of the HTTP response line and headers must end with CRLF). Cannot be
|
|
|
|
used in conjunction with B<-early_data>.
|
2012-11-20 00:37:18 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-id_prefix> I<val>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Generate SSL/TLS session IDs prefixed by I<val>. This is mostly useful
|
2017-06-07 18:43:03 +08:00
|
|
|
for testing any SSL/TLS code (eg. proxies) that wish to deal with multiple
|
|
|
|
servers, when each of which might be generating a unique range of session
|
|
|
|
IDs (eg. with a certain prefix).
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-verify_return_error>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Verification errors normally just print a message but allow the
|
|
|
|
connection to continue, for debugging purposes.
|
|
|
|
If this option is used, then verification errors close the connection.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-status>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Enables certificate status request support (aka OCSP stapling).
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-status_verbose>
|
2006-03-11 07:06:27 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Enables certificate status request support (aka OCSP stapling) and gives
|
|
|
|
a verbose printout of the OCSP response.
|
2006-03-11 07:06:27 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-status_timeout> I<int>
|
2017-06-02 09:01:27 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Sets the timeout for OCSP response to I<int> seconds.
|
2017-06-02 09:01:27 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-status_url> I<val>
|
2006-03-11 07:06:27 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Sets a fallback responder URL to use if no responder URL is present in the
|
|
|
|
server certificate. Without this option an error is returned if the server
|
|
|
|
certificate does not contain a responder address.
|
2006-03-11 07:06:27 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-status_file> I<infile>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Overrides any OCSP responder URLs from the certificate and always provides the
|
|
|
|
OCSP Response stored in the file. The file must be in DER format.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-trace>
|
2015-04-10 20:10:05 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Show verbose trace output of protocol messages. OpenSSL needs to be compiled
|
|
|
|
with B<enable-ssl-trace> for this option to work.
|
2015-04-10 20:10:05 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-brief>
|
2015-04-10 20:10:05 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Provide a brief summary of connection parameters instead of the normal verbose
|
|
|
|
output.
|
2015-04-10 20:10:05 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-rev>
|
2017-04-25 21:37:25 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Simple test server which just reverses the text received from the client
|
2018-09-13 00:11:10 +08:00
|
|
|
and sends it back to the server. Also sets B<-brief>. Cannot be used in
|
|
|
|
conjunction with B<-early_data>.
|
2017-04-25 21:37:25 +08:00
|
|
|
|
2015-10-06 20:48:43 +08:00
|
|
|
=item B<-async>
|
|
|
|
|
2016-02-22 05:37:14 +08:00
|
|
|
Switch on asynchronous mode. Cryptographic operations will be performed
|
2015-10-06 20:48:43 +08:00
|
|
|
asynchronously. This will only have an effect if an asynchronous capable engine
|
|
|
|
is also used via the B<-engine> option. For test purposes the dummy async engine
|
|
|
|
(dasync) can be used (if available).
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-max_send_frag> I<+int>
|
2017-04-07 05:47:18 +08:00
|
|
|
|
|
|
|
The maximum size of data fragment to send.
|
|
|
|
See L<SSL_CTX_set_max_send_fragment(3)> for further information.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-split_send_frag> I<+int>
|
2016-02-16 19:13:33 +08:00
|
|
|
|
|
|
|
The size used to split data for encrypt pipelines. If more data is written in
|
|
|
|
one go than this value then it will be split into multiple pipelines, up to the
|
|
|
|
maximum number of pipelines defined by max_pipelines. This only has an effect if
|
2017-03-30 05:38:30 +08:00
|
|
|
a suitable cipher suite has been negotiated, an engine that supports pipelining
|
2016-02-16 19:13:33 +08:00
|
|
|
has been loaded, and max_pipelines is greater than 1. See
|
|
|
|
L<SSL_CTX_set_split_send_fragment(3)> for further information.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-max_pipelines> I<+int>
|
2016-02-16 19:13:33 +08:00
|
|
|
|
|
|
|
The maximum number of encrypt/decrypt pipelines to be used. This will only have
|
|
|
|
an effect if an engine has been loaded that supports pipelining (e.g. the dasync
|
2017-03-30 05:38:30 +08:00
|
|
|
engine) and a suitable cipher suite has been negotiated. The default value is 1.
|
2016-02-16 19:13:33 +08:00
|
|
|
See L<SSL_CTX_set_max_pipelines(3)> for further information.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-read_buf> I<+int>
|
2016-02-16 19:13:33 +08:00
|
|
|
|
|
|
|
The default read buffer size to be used for connections. This will only have an
|
|
|
|
effect if the buffer size is larger than the size that would otherwise be used
|
|
|
|
and pipelining is in use (see L<SSL_CTX_set_default_read_buffer_len(3)> for
|
|
|
|
further information).
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-ssl2>, B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>, B<-no_ssl2>, B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3>
|
|
|
|
|
|
|
|
These options require or disable the use of the specified SSL or TLS protocols.
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
By default, this command will negotiate the highest mutually supported
|
|
|
|
protocol version.
|
2017-06-07 18:43:03 +08:00
|
|
|
When a specific TLS version is required, only that version will be accepted
|
|
|
|
from the client.
|
2018-07-31 23:36:44 +08:00
|
|
|
Note that not all protocols and flags may be available, depending on how
|
|
|
|
OpenSSL was built.
|
2017-06-07 18:43:03 +08:00
|
|
|
|
2000-01-09 09:26:43 +08:00
|
|
|
=item B<-bugs>
|
|
|
|
|
2019-03-27 07:55:55 +08:00
|
|
|
There are several known bugs in SSL and TLS implementations. Adding this
|
2000-01-09 09:26:43 +08:00
|
|
|
option enables various workarounds.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-no_comp>
|
|
|
|
|
|
|
|
Disable negotiation of TLS compression.
|
|
|
|
TLS compression is not recommended and is off by default as of
|
|
|
|
OpenSSL 1.1.0.
|
|
|
|
|
2016-02-04 05:45:39 +08:00
|
|
|
=item B<-comp>
|
|
|
|
|
|
|
|
Enable negotiation of TLS compression.
|
|
|
|
This option was introduced in OpenSSL 1.1.0.
|
|
|
|
TLS compression is not recommended and is off by default as of
|
|
|
|
OpenSSL 1.1.0.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-no_ticket>
|
2016-02-04 05:45:39 +08:00
|
|
|
|
2018-12-04 20:31:17 +08:00
|
|
|
Disable RFC4507bis session ticket support. This option has no effect if TLSv1.3
|
|
|
|
is negotiated. See B<-num_tickets>.
|
|
|
|
|
|
|
|
=item B<-num_tickets>
|
|
|
|
|
|
|
|
Control the number of tickets that will be sent to the client after a full
|
|
|
|
handshake in TLSv1.3. The default number of tickets is 2. This option does not
|
|
|
|
affect the number of tickets sent after a resumption handshake.
|
2016-02-04 05:45:39 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-serverpref>
|
2012-11-20 00:07:53 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Use the server's cipher preferences, rather than the client's preferences.
|
|
|
|
|
2015-12-22 04:19:29 +08:00
|
|
|
=item B<-prioritize_chacha>
|
|
|
|
|
|
|
|
Prioritize ChaCha ciphers when preferred by clients. Requires B<-serverpref>.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-no_resumption_on_reneg>
|
|
|
|
|
|
|
|
Set the B<SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION> option.
|
2012-11-20 00:07:53 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-client_sigalgs> I<val>
|
2017-03-29 00:02:37 +08:00
|
|
|
|
|
|
|
Signature algorithms to support for client certificate authentication
|
2017-03-30 05:38:30 +08:00
|
|
|
(colon-separated list).
|
2017-03-29 00:02:37 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-named_curve> I<val>
|
2017-03-29 00:02:37 +08:00
|
|
|
|
|
|
|
Specifies the elliptic curve to use. NOTE: this is single curve, not a list.
|
|
|
|
For a list of all possible curves, use:
|
|
|
|
|
|
|
|
$ openssl ecparam -list_curves
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-cipher> I<val>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2018-02-22 01:23:11 +08:00
|
|
|
This allows the list of TLSv1.2 and below ciphersuites used by the server to be
|
|
|
|
modified. This list is combined with any TLSv1.3 ciphersuites that have been
|
|
|
|
configured. When the client sends a list of supported ciphers the first client
|
|
|
|
cipher also included in the server list is used. Because the client specifies
|
|
|
|
the preference order, the order of the server cipherlist is irrelevant. See
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
L<openssl-ciphers(1)> for more information.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-ciphersuites> I<val>
|
2018-02-22 01:23:11 +08:00
|
|
|
|
|
|
|
This allows the list of TLSv1.3 ciphersuites used by the server to be modified.
|
|
|
|
This list is combined with any TLSv1.2 and below ciphersuites that have been
|
|
|
|
configured. When the client sends a list of supported ciphers the first client
|
|
|
|
cipher also included in the server list is used. Because the client specifies
|
|
|
|
the preference order, the order of the server cipherlist is irrelevant. See
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
L<openssl-ciphers(1)> command for more information. The format for this list is
|
|
|
|
a simple colon (":") separated list of TLSv1.3 ciphersuite names.
|
2018-02-22 01:23:11 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-dhparam> I<infile>
|
2001-03-11 00:28:49 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
The DH parameter file to use. The ephemeral DH cipher suites generate keys
|
|
|
|
using a set of DH parameters. If not specified then an attempt is made to
|
|
|
|
load the parameters from the server certificate file.
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
If this fails then a static set of parameters hard coded into this command
|
|
|
|
will be used.
|
2012-11-20 00:07:53 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-attime>, B<-check_ss_sig>, B<-crl_check>, B<-crl_check_all>,
|
|
|
|
B<-explicit_policy>, B<-extended_crl>, B<-ignore_critical>, B<-inhibit_any>,
|
|
|
|
B<-inhibit_map>, B<-no_alt_chains>, B<-no_check_time>, B<-partial_chain>, B<-policy>,
|
|
|
|
B<-policy_check>, B<-policy_print>, B<-purpose>, B<-suiteB_128>,
|
|
|
|
B<-suiteB_128_only>, B<-suiteB_192>, B<-trusted_first>, B<-use_deltas>,
|
|
|
|
B<-auth_level>, B<-verify_depth>, B<-verify_email>, B<-verify_hostname>,
|
|
|
|
B<-verify_ip>, B<-verify_name>, B<-x509_strict>
|
2000-10-27 05:07:28 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Set different peer certificate verification options.
|
2019-10-02 03:57:00 +08:00
|
|
|
See the L<openssl-verify(1)> manual page for details.
|
2000-10-27 05:07:28 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-crl_check>, B<-crl_check_all>
|
2003-03-21 00:34:27 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Check the peer certificate has not been revoked by its CA.
|
|
|
|
The CRL(s) are appended to the certificate file. With the B<-crl_check_all>
|
|
|
|
option all CRLs of all CAs in the chain are checked.
|
2003-03-21 00:34:27 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-nbio>
|
2001-02-15 18:22:07 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Turns on non blocking I/O.
|
2001-02-15 18:22:07 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-psk_identity> I<val>
|
2013-06-14 13:36:45 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Expect the client to send PSK identity I<val> when using a PSK
|
2017-06-07 18:43:03 +08:00
|
|
|
cipher suite, and warn if they do not. By default, the expected PSK
|
|
|
|
identity is the string "Client_identity".
|
2013-06-14 13:36:45 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-psk_hint> I<val>
|
2013-06-19 05:34:38 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Use the PSK identity hint I<val> when using a PSK cipher suite.
|
2013-06-19 05:34:38 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-psk> I<val>
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Use the PSK key I<val> when using a PSK cipher suite. The key is
|
2017-06-07 18:43:03 +08:00
|
|
|
given as a hexadecimal number without leading 0x, for example -psk
|
|
|
|
1a2b3c4d.
|
|
|
|
This option must be provided in order to use a PSK cipher.
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-psk_session> I<file>
|
2018-05-10 19:01:06 +08:00
|
|
|
|
2019-10-02 00:16:29 +08:00
|
|
|
Use the pem encoded SSL_SESSION data stored in I<file> as the basis of a PSK.
|
2018-05-10 19:01:06 +08:00
|
|
|
Note that this will only work if TLSv1.3 is negotiated.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-listen>
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
This option can only be used in conjunction with one of the DTLS options above.
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
With this option, this command will listen on a UDP port for incoming
|
|
|
|
connections.
|
2017-06-07 18:43:03 +08:00
|
|
|
Any ClientHellos that arrive will be checked to see if they have a cookie in
|
|
|
|
them or not.
|
|
|
|
Any without a cookie will be responded to with a HelloVerifyRequest.
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
If a ClientHello with a cookie is received then this command will
|
|
|
|
connect to that peer and complete the handshake.
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-dtls>, B<-dtls1>, B<-dtls1_2>
|
2014-07-07 05:16:21 +08:00
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
These options make this command use DTLS protocols instead of TLS.
|
|
|
|
With B<-dtls>, it will negotiate any supported DTLS protocol
|
|
|
|
version, whilst B<-dtls1> and B<-dtls1_2> will only support DTLSv1.0 and
|
|
|
|
DTLSv1.2 respectively.
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-sctp>
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
Use SCTP for the transport protocol instead of UDP in DTLS. Must be used in
|
|
|
|
conjunction with B<-dtls>, B<-dtls1> or B<-dtls1_2>. This option is only
|
|
|
|
available where OpenSSL has support for SCTP enabled.
|
2014-07-07 05:16:21 +08:00
|
|
|
|
2018-12-26 19:44:53 +08:00
|
|
|
=item B<-sctp_label_bug>
|
|
|
|
|
|
|
|
Use the incorrect behaviour of older OpenSSL implementations when computing
|
|
|
|
endpoint-pair shared secrets for DTLS/SCTP. This allows communication with
|
|
|
|
older broken implementations but breaks interoperability with correct
|
|
|
|
implementations. Must be used in conjunction with B<-sctp>. This option is only
|
|
|
|
available where OpenSSL has support for SCTP enabled.
|
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
=item B<-no_dhe>
|
2016-11-15 22:22:29 +08:00
|
|
|
|
2017-06-07 18:43:03 +08:00
|
|
|
If this option is set then no DH parameters will be loaded effectively
|
|
|
|
disabling the ephemeral DH cipher suites.
|
2016-11-15 22:22:29 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-alpn> I<val>, B<-nextprotoneg> I<val>
|
2014-06-06 22:48:43 +08:00
|
|
|
|
2017-03-30 05:38:30 +08:00
|
|
|
These flags enable the Enable the Application-Layer Protocol Negotiation
|
|
|
|
or Next Protocol Negotiation (NPN) extension, respectively. ALPN is the
|
|
|
|
IETF standard and replaces NPN.
|
2019-10-02 00:16:29 +08:00
|
|
|
The I<val> list is a comma-separated list of supported protocol
|
2017-03-30 05:38:30 +08:00
|
|
|
names. The list should contain the most desirable protocols first.
|
2014-06-06 22:48:43 +08:00
|
|
|
Protocol names are printable ASCII strings, for example "http/1.1" or
|
|
|
|
"spdy/3".
|
2017-06-16 18:12:02 +08:00
|
|
|
The flag B<-nextprotoneg> cannot be specified if B<-tls1_3> is used.
|
2014-06-06 22:48:43 +08:00
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-keylogfile> I<outfile>
|
2017-03-18 02:17:57 +08:00
|
|
|
|
|
|
|
Appends TLS secrets to the specified keylog file such that external programs
|
|
|
|
(like Wireshark) can decrypt TLS connections.
|
|
|
|
|
2019-09-26 03:20:11 +08:00
|
|
|
=item B<-max_early_data> I<int>
|
2017-02-25 00:17:00 +08:00
|
|
|
|
|
|
|
Change the default maximum early data bytes that are specified for new sessions
|
|
|
|
and any incoming early data (when used in conjunction with the B<-early_data>
|
2017-03-03 01:40:43 +08:00
|
|
|
flag). The default value is approximately 16k. The argument must be an integer
|
|
|
|
greater than or equal to 0.
|
2017-02-25 00:17:00 +08:00
|
|
|
|
|
|
|
=item B<-early_data>
|
|
|
|
|
2018-09-13 00:11:10 +08:00
|
|
|
Accept early data where possible. Cannot be used in conjunction with B<-www>,
|
|
|
|
B<-WWW>, B<-HTTP> or B<-rev>.
|
2017-02-25 00:17:00 +08:00
|
|
|
|
2018-06-15 21:55:06 +08:00
|
|
|
=item B<-anti_replay>, B<-no_anti_replay>
|
|
|
|
|
|
|
|
Switches replay protection on or off, respectively. Replay protection is on by
|
|
|
|
default unless overridden by a configuration file. When it is on, OpenSSL will
|
|
|
|
automatically detect if a session ticket has been used more than once, TLSv1.3
|
|
|
|
has been negotiated, and early data is enabled on the server. A full handshake
|
|
|
|
is forced if a session ticket is used a second or subsequent time. Any early
|
|
|
|
data that was sent will be rejected.
|
|
|
|
|
2019-05-09 07:16:19 +08:00
|
|
|
=item B<-http_server_binmode>
|
|
|
|
|
|
|
|
When acting as web-server (using option B<-WWW> or B<-HTTP>) open files requested
|
|
|
|
by the client in binary mode.
|
|
|
|
|
2019-10-25 11:02:09 +08:00
|
|
|
{- $OpenSSL::safe::opt_name_item -}
|
|
|
|
|
2019-10-13 05:45:56 +08:00
|
|
|
{- $OpenSSL::safe::opt_x_item -}
|
|
|
|
|
|
|
|
{- $OpenSSL::safe::opt_trust_item -}
|
|
|
|
|
|
|
|
{- $OpenSSL::safe::opt_r_item -}
|
|
|
|
|
2019-10-13 05:45:56 +08:00
|
|
|
{- $OpenSSL::safe::opt_engine_item -}
|
|
|
|
|
2000-01-09 09:26:43 +08:00
|
|
|
=back
|
|
|
|
|
|
|
|
=head1 CONNECTED COMMANDS
|
|
|
|
|
|
|
|
If a connection request is established with an SSL client and neither the
|
2000-01-10 08:11:51 +08:00
|
|
|
B<-www> nor the B<-WWW> option has been used then normally any data received
|
2016-02-22 05:37:14 +08:00
|
|
|
from the client is displayed and any key presses will be sent to the client.
|
2000-01-10 08:11:51 +08:00
|
|
|
|
2018-05-22 22:18:01 +08:00
|
|
|
Certain commands are also recognized which perform special operations. These
|
|
|
|
commands are a letter which must appear at the start of a line. They are listed
|
|
|
|
below.
|
2000-01-10 08:11:51 +08:00
|
|
|
|
|
|
|
=over 4
|
|
|
|
|
|
|
|
=item B<q>
|
|
|
|
|
2017-03-30 05:38:30 +08:00
|
|
|
End the current SSL connection but still accept new connections.
|
2000-01-10 08:11:51 +08:00
|
|
|
|
|
|
|
=item B<Q>
|
|
|
|
|
2017-03-30 05:38:30 +08:00
|
|
|
End the current SSL connection and exit.
|
2000-01-10 08:11:51 +08:00
|
|
|
|
|
|
|
=item B<r>
|
|
|
|
|
2018-05-22 22:18:01 +08:00
|
|
|
Renegotiate the SSL session (TLSv1.2 and below only).
|
2000-01-10 08:11:51 +08:00
|
|
|
|
|
|
|
=item B<R>
|
|
|
|
|
2018-05-22 22:18:01 +08:00
|
|
|
Renegotiate the SSL session and request a client certificate (TLSv1.2 and below
|
|
|
|
only).
|
2000-01-10 08:11:51 +08:00
|
|
|
|
|
|
|
=item B<P>
|
|
|
|
|
2017-03-30 05:38:30 +08:00
|
|
|
Send some plain text down the underlying TCP connection: this should
|
2000-01-10 08:11:51 +08:00
|
|
|
cause the client to disconnect due to a protocol violation.
|
|
|
|
|
|
|
|
=item B<S>
|
|
|
|
|
2017-03-30 05:38:30 +08:00
|
|
|
Print out some session cache status information.
|
2000-01-10 08:11:51 +08:00
|
|
|
|
2018-05-22 22:18:01 +08:00
|
|
|
=item B<k>
|
|
|
|
|
|
|
|
Send a key update message to the client (TLSv1.3 only)
|
|
|
|
|
|
|
|
=item B<K>
|
|
|
|
|
|
|
|
Send a key update message to the client and request one back (TLSv1.3 only)
|
|
|
|
|
|
|
|
=item B<c>
|
|
|
|
|
|
|
|
Send a certificate request to the client (TLSv1.3 only)
|
|
|
|
|
2000-01-10 08:11:51 +08:00
|
|
|
=back
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
=head1 NOTES
|
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
This command can be used to debug SSL clients. To accept connections
|
|
|
|
from a web browser the command:
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
openssl s_server -accept 443 -www
|
|
|
|
|
|
|
|
can be used for example.
|
|
|
|
|
|
|
|
Although specifying an empty list of CAs when requesting a client certificate
|
2000-01-10 08:11:51 +08:00
|
|
|
is strictly speaking a protocol violation, some SSL clients interpret this to
|
|
|
|
mean any CA is acceptable. This is useful for debugging purposes.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
The session parameters can printed out using the L<openssl-sess_id(1)> command.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
=head1 BUGS
|
|
|
|
|
2016-02-22 05:37:14 +08:00
|
|
|
Because this program has a lot of options and also because some of the
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
techniques used are rather old, the C source for this command is rather
|
|
|
|
hard to read and not a model of how things should be done.
|
2016-02-22 05:37:14 +08:00
|
|
|
A typical SSL server program would be much simpler.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
The output of common ciphers is wrong: it just gives the list of ciphers that
|
2000-01-10 08:11:51 +08:00
|
|
|
OpenSSL recognizes and the client supports.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
Command docs: fix up command references
Almost all OpenSSL commands are in reality 'openssl cmd', so make sure
they are refered to like that and not just as the sub-command.
Self-references are avoided as much as is possible, and replaced with
"this command". In some cases, we even avoid that with a slight
rewrite of the sentence or paragrah they were in. However, in the few
cases where a self-reference is still admissible, they are done in
bold, i.e. openssl-speed.pod references itself like this:
B<openssl speed>
References to other commands are done as manual links, i.e. CA.pl.pod
references 'openssl req' like this: L<openssl-req(1)>
Some commands are examples rather than references; we enclose those in
C<>.
While we are it, we abolish "utility", replacing it with "command", or
remove it entirely in some cases.
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
(Merged from https://github.com/openssl/openssl/pull/10065)
2019-10-02 01:43:36 +08:00
|
|
|
There should be a way for this command to print out details
|
|
|
|
of any unknown cipher suites a client says it supports.
|
2000-01-09 09:26:43 +08:00
|
|
|
|
|
|
|
=head1 SEE ALSO
|
|
|
|
|
2019-08-22 07:04:41 +08:00
|
|
|
L<openssl(1)>,
|
|
|
|
L<openssl-sess_id(1)>,
|
|
|
|
L<openssl-s_client(1)>,
|
|
|
|
L<openssl-ciphers(1)>,
|
|
|
|
L<SSL_CONF_cmd(3)>,
|
2018-07-04 00:45:14 +08:00
|
|
|
L<SSL_CTX_set_max_send_fragment(3)>,
|
|
|
|
L<SSL_CTX_set_split_send_fragment(3)>,
|
2019-03-07 22:26:34 +08:00
|
|
|
L<SSL_CTX_set_max_pipelines(3)>,
|
|
|
|
L<ossl_store-file(7)>
|
2000-01-09 09:26:43 +08:00
|
|
|
|
2015-01-27 19:15:15 +08:00
|
|
|
=head1 HISTORY
|
|
|
|
|
2018-12-09 08:02:36 +08:00
|
|
|
The -no_alt_chains option was added in OpenSSL 1.1.0.
|
2015-12-22 04:19:29 +08:00
|
|
|
|
2018-12-09 08:02:36 +08:00
|
|
|
The
|
|
|
|
-allow-no-dhe-kex and -prioritize_chacha options were added in OpenSSL 1.1.1.
|
2015-01-27 19:15:15 +08:00
|
|
|
|
2016-05-18 23:44:05 +08:00
|
|
|
=head1 COPYRIGHT
|
|
|
|
|
2019-08-22 07:04:41 +08:00
|
|
|
Copyright 2000-2019 The OpenSSL Project Authors. All Rights Reserved.
|
2016-05-18 23:44:05 +08:00
|
|
|
|
2018-12-06 21:04:11 +08:00
|
|
|
Licensed under the Apache License 2.0 (the "License"). You may not use
|
2016-05-18 23:44:05 +08:00
|
|
|
this file except in compliance with the License. You can obtain a copy
|
|
|
|
in the file LICENSE in the source distribution or at
|
|
|
|
L<https://www.openssl.org/source/license.html>.
|
|
|
|
|
|
|
|
=cut
|