Documentation for the -precert flag for "openssl req"

Reviewed-by: Tim Hudson <tjh@openssl.org>
Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/843)
This commit is contained in:
Rob Percival 2016-03-10 20:32:16 +00:00 committed by Rich Salz
parent caee75d2c6
commit 7bb89f094d

View File

@ -37,6 +37,7 @@ B<openssl> B<req>
[B<-newhdr>]
[B<-extensions section>]
[B<-reqexts section>]
[B<-precert>]
[B<-utf8>]
[B<-nameopt>]
[B<-reqopt>]
@ -253,6 +254,14 @@ request extensions. This allows several different sections to
be used in the same configuration file to specify requests for
a variety of purposes.
=item B<-precert>
a poison extension will be added to the certificate, making it a
"pre-certificate" (see RFC6962). This can be submitted to Certificate
Transparency logs in order to obtain signed certificate timestamps (SCTs).
These SCTs can then be embedded into the pre-certificate as an extension, before
removing the poison and signing the certificate.
=item B<-utf8>
this option causes field values to be interpreted as UTF8 strings, by