Commit b197c770 authored by Dr. Stephen Henson's avatar Dr. Stephen Henson
Browse files

Document certificate status request options.

(cherry picked from commit cba3f1c7)

Conflicts:

	doc/apps/s_client.pod
	doc/apps/s_server.pod
parent b7c97625
Loading
Loading
Loading
Loading
+6 −0
Original line number Diff line number Diff line
@@ -47,6 +47,7 @@ B<openssl> B<s_client>
[B<-sess_out filename>]
[B<-sess_in filename>]
[B<-rand file(s)>]
[B<-status>]

=head1 DESCRIPTION

@@ -259,6 +260,11 @@ Multiple files can be specified separated by a OS-dependent character.
The separator is B<;> for MS-Windows, B<,> for OpenVMS, and B<:> for
all others.

=item B<-status>

sends a certificate status request to the server (OCSP stapling). The server
response (if any) is printed out.

=back

=head1 CONNECTED COMMANDS
+23 −0
Original line number Diff line number Diff line
@@ -56,6 +56,10 @@ B<openssl> B<s_server>
[B<-no_ticket>]
[B<-id_prefix arg>]
[B<-rand file(s)>]
[B<-status>]
[B<-status_verbose>]
[B<-status_timeout nsec>]
[B<-status_url url>]

=head1 DESCRIPTION

@@ -287,6 +291,25 @@ Multiple files can be specified separated by a OS-dependent character.
The separator is B<;> for MS-Windows, B<,> for OpenVMS, and B<:> for
all others.

=item B<-status>

enables certificate status request support (aka OCSP stapling).

=item B<-status_verbose>

enables certificate status request support (aka OCSP stapling) and gives
a verbose printout of the OCSP response.

=item B<-status_timeout nsec>

sets the timeout for OCSP response to B<nsec> seconds.

=item B<-status_url url>

sets a fallback responder URL to use if no responder URL is present in the
server certificate. Without this option an error is returned if the server
certificate does not contain a responder address.

=back

=head1 CONNECTED COMMANDS