X-Git-Url: https://git.ozlabs.org/?p=ppp.git;a=blobdiff_plain;f=README.eap-tls;h=7895b2b2eaa15c53f70aeca06f52f7dd9c92d4b6;hp=ab3794eaa53566e7a3e72805cce1b4c5988f154b;hb=HEAD;hpb=b5599f6001d9b024b3a572ab62c92027d94f052f diff --git a/README.eap-tls b/README.eap-tls index ab3794e..ad81ab2 100644 --- a/README.eap-tls +++ b/README.eap-tls @@ -126,7 +126,7 @@ EAP-TLS authentication support for PPP ca Use the CA public certificate found in in PEM format - ca-path + capath Use the directory as the CA public certificate directory cert Use the client public certificate found in in PEM format @@ -134,6 +134,9 @@ EAP-TLS authentication support for PPP key Use the client private key found in in PEM format or in engine:engine_id format + pkcs12 + Use a pkcs12 envelope as a substitute for cert and key. A password may be + required to use this file. crl Use the Certificate Revocation List (CRL) file in PEM format. crl-dir @@ -147,6 +150,11 @@ EAP-TLS authentication support for PPP max-tls-version <1.0|1.1|1.2 (default)|1.3> Specify the maximum TLS protocol version to negotiate with peers. Defaults to TLSv1.2 as the TLSv1.3 code is experimental. + tls-verify-key-usage + Validate certificate purpose and extended key usage + tls-verify-method + Compare the remotename against the subject, certificate name, or + match by suffix. Default is 'name'. Note: password-encrypted certificates can be used as of v0.94 of this