ITS#9687 TLSECName is no longer required with OpenSSL 1.1+

This commit is contained in:
Howard Chu 2021-09-14 17:56:03 +01:00
parent f38b7b9f49
commit a7717ae753

View file

@ -160,12 +160,13 @@ or
H4: TLSECName <name>
This directive specifies the curve to use for Elliptic Curve
Diffie-Hellman ephemeral key exchange. This is required in order
Diffie-Hellman ephemeral key exchange. This option is only needed
to use ECDHE-based cipher suites in OpenSSL. The names of supported
curves may be shown using the following command
> openssl ecparam -list_curves
If it is omitted, OpenSSL will auto-negotiate the curve choice.
This directive is not used for GnuTLS.
For GnuTLS the curves may be specified in the ciphersuite.