Index: openssl/doc/apps/s_client.pod |
=================================================================== |
--- openssl/doc/apps/s_client.pod (revision 105093) |
+++ openssl/doc/apps/s_client.pod (working copy) |
@@ -101,6 +101,11 @@ |
A file containing trusted certificates to use during server authentication |
and to use when attempting to build the client certificate chain. |
+=item B<-purpose, -ignore_critical, -issuer_checks, -crl_check, -crl_check_all, -policy_check, -extended_crl, -x509_strict, -policy -check_ss_sig> |
+ |
+Set various certificate chain valiadition option. See the |
+L<B<verify>|verify(1)> manual page for details. |
+ |
=item B<-reconnect> |
reconnects to the same server 5 times using the same session ID, this can |
@@ -161,6 +166,16 @@ |
inhibit printing of session and certificate information. This implicitly |
turns on B<-ign_eof> as well. |
+=item B<-psk_identity identity> |
+ |
+Use the PSK identity B<identity> when using a PSK cipher suite. |
+ |
+=item B<-psk key> |
+ |
+Use the PSK key B<key> when using a PSK cipher suite. The key is |
+given as a hexadecimal number without leading 0x, for example -psk |
+1a2b3c4d. |
+ |
=item B<-ssl2>, B<-ssl3>, B<-tls1>, B<-no_ssl2>, B<-no_ssl3>, B<-no_tls1> |
these options disable the use of certain SSL or TLS protocols. By default |
@@ -192,14 +207,11 @@ |
=item B<-tlsextdebug> |
-print out a hex dump of any TLS extensions received from the server. Note: this |
-option is only available if extension support is explicitly enabled at compile |
-time |
+print out a hex dump of any TLS extensions received from the server. |
=item B<-no_ticket> |
-disable RFC4507bis session ticket support. Note: this option is only available |
-if extension support is explicitly enabled at compile time |
+disable RFC4507bis session ticket support. |
=item B<-sess_out filename> |
@@ -212,7 +224,7 @@ |
=item B<-engine id> |
-specifying an engine (by it's unique B<id> string) will cause B<s_client> |
+specifying an engine (by its unique B<id> string) will cause B<s_client> |
to attempt to obtain a functional reference to the specified engine, |
thus initialising it if needed. The engine will then be set as the default |
for all available algorithms. |
@@ -274,9 +286,6 @@ |
these will only be supported if its use is disabled, for example by using the |
B<-no_sslv2> option. |
-TLS extensions are only supported in OpenSSL 0.9.8 if they are explictly |
-enabled at compile time using for example the B<enable-tlsext> switch. |
- |
=head1 BUGS |
Because this program has a lot of options and also because some of |