summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPauli <paul.dale@oracle.com>2019-09-21 10:29:17 +1000
committerPauli <paul.dale@oracle.com>2019-09-21 21:20:18 +1000
commita941054ad7f5af9445896a37754ae451fad7ed98 (patch)
tree099e4da2ad9dbf1afaef0e617eeb1ddc7a746c88
parent387bbce45bfe9c0bccbd2c84206ca7719d463740 (diff)
Note that the mac command is preferrable to the MAC command line options.
The dgst command allows MACs to be calculated, the mac command is the more recent interface for doing the same and provides better access to a wider range of MACs. Reviewed-by: Richard Levitte <levitte@openssl.org> Reviewed-by: Matthias St. Pierre <Matthias.St.Pierre@ncp-e.com> (Merged from https://github.com/openssl/openssl/pull/9962)
-rw-r--r--doc/man1/openssl-dgst.pod16
1 files changed, 16 insertions, 0 deletions
diff --git a/doc/man1/openssl-dgst.pod b/doc/man1/openssl-dgst.pod
index ed1a088e6e..5fb5128a02 100644
--- a/doc/man1/openssl-dgst.pod
+++ b/doc/man1/openssl-dgst.pod
@@ -123,6 +123,9 @@ The actual signature to verify.
Create a hashed MAC using "key".
+The L<openssl-mac(1)> command should be preferred to using this command line
+option.
+
=item B<-mac alg>
Create MAC (keyed Message Authentication Code). The most popular MAC
@@ -131,6 +134,9 @@ which are not based on hash, for instance B<gost-mac> algorithm,
supported by B<ccgost> engine. MAC keys and other options should be set
via B<-macopt> parameter.
+The L<openssl-mac(1)> command should be preferred to using this command line
+option.
+
=item B<-macopt nm:v>
Passes options to MAC algorithm, specified by B<-mac> key.
@@ -152,6 +158,9 @@ for example exactly 32 chars for gost-mac.
=back
+The L<openssl-mac(1)> command should be preferred to using this command line
+option.
+
=item B<-rand file...>
A file or files containing random data used to seed the random number
@@ -229,6 +238,13 @@ Hex signatures cannot be verified using B<openssl>. Instead, use "xxd -r"
or similar program to transform the hex signature into a binary signature
prior to verification.
+The L<openssl-mac(1)> command is preferred over the B<-hmac>, B<-mac> and
+B<-macopt> command line options.
+
+=head1 SEE ALSO
+
+L<openssl-mac(1)>
+
=head1 HISTORY
The default digest was changed from MD5 to SHA256 in OpenSSL 1.1.0.