提交 bbe9c3d5 编写于 作者: J Johannes Bauer 提交者: Rich Salz

Clarify CLI OCSP documentation

This fixes issue #3043, which ultimately was reported because
documentation was not clear on the meaning of the "-ignore_err" option.
Update both command line documentation and add this option to manpage.
Reviewed-by: NAndy Polyakov <appro@openssl.org>
Reviewed-by: NRich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4143)
上级 44e69951
......@@ -108,7 +108,7 @@ const OPTIONS ocsp_options[] = {
{"host", OPT_HOST, 's', "TCP/IP hostname:port to connect to"},
{"port", OPT_PORT, 'p', "Port to run responder on"},
{"ignore_err", OPT_IGNORE_ERR, '-',
"Ignore Error response from OCSP responder, and retry "},
"Ignore error on OCSP request or response and continue running"},
{"noverify", OPT_NOVERIFY, '-', "Don't verify response at all"},
{"nonce", OPT_NONCE, '-', "Add OCSP nonce to request"},
{"no_nonce", OPT_NO_NONCE, '-', "Don't add OCSP nonce to request"},
......
......@@ -74,6 +74,7 @@ B<openssl> B<ocsp>
[B<-no_cert_checks>]
[B<-no_explicit>]
[B<-port num>]
[B<-ignore_err>]
[B<-index file>]
[B<-CA file>]
[B<-rsigner file>]
......@@ -343,6 +344,12 @@ specified in the B<rsigner> option is used.
Port to listen for OCSP requests on. The port may also be specified
using the B<url> option.
=item B<-ignore_err>
Ignore malformed requests or responses: When acting as an OCSP client, retry if
a malformed response is received. When acting as an OCSP responder, continue
running instead of terminating upon receiving a malformed request.
=item B<-nrequest number>
The OCSP server will exit after receiving B<number> requests, default unlimited.
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册