summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorolszomal <Malgorzata.Olszowka@stunnel.org>2024-02-08 14:30:22 +0100
committerTomas Mraz <tomas@openssl.org>2024-03-12 14:02:13 +0100
commit7ceb770883d5bbb60868df46a699dff928f865aa (patch)
tree3c4811c56a10a9f81d76bfd601360ff1c145f1b3
parentd6aafeb1076ed4eeda1b0ced11207e05b0e32b0d (diff)
Improve the documentation on -cert_chain and -status_verbose options
Reviewed-by: Matt Caswell <matt@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.org> (Merged from https://github.com/openssl/openssl/pull/22192)
-rw-r--r--doc/man1/openssl-s_server.pod.in4
1 files changed, 4 insertions, 0 deletions
diff --git a/doc/man1/openssl-s_server.pod.in b/doc/man1/openssl-s_server.pod.in
index 6b9c91ba87..268eca066b 100644
--- a/doc/man1/openssl-s_server.pod.in
+++ b/doc/man1/openssl-s_server.pod.in
@@ -232,6 +232,8 @@ See L<openssl-format-options(1)> for details.
A file or URI of untrusted certificates to use when attempting to build the
certificate chain related to the certificate specified via the B<-cert> option.
+These untrusted certificates are sent to clients and used for generating
+certificate status (aka OCSP stapling) requests.
The input can be in PEM, DER, or PKCS#12 format.
=item B<-build_chain>
@@ -513,6 +515,8 @@ Enables certificate status request support (aka OCSP stapling).
Enables certificate status request support (aka OCSP stapling) and gives
a verbose printout of the OCSP response.
+Use the B<-cert_chain> option to specify the certificate of the server's
+certificate signer that is required for certificate status requests.
=item B<-status_timeout> I<int>