From: Dr. Stephen Henson Date: Wed, 7 Dec 2011 00:42:22 +0000 (+0000) Subject: Document RFC5114 "generation" options. X-Git-Tag: master-post-reformat~2059 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=618eb125f01c64640ff86f343c9dc1d037499175;p=oweals%2Fopenssl.git Document RFC5114 "generation" options. --- diff --git a/doc/apps/genpkey.pod b/doc/apps/genpkey.pod index 1611b5ca78..84f9edb2d7 100644 --- a/doc/apps/genpkey.pod +++ b/doc/apps/genpkey.pod @@ -126,6 +126,15 @@ The number of bits in the prime parameter B

. The value to use for the generator B. +=item B + +If this option is set then the appropriate RFC5114 parameters are used +instead of generating new parameters. The value B can take the +values 1, 2 or 3 corresponding to RFC5114 DH parameters consisting of +1024 bit group with 160 bit subgroup, 2048 bit group with 224 bit subgroup +and 2048 bit group with 256 bit subgroup as mentioned in RFC5114 sections +2.1, 2.2 and 2.3 respectively. + =back =head1 EC PARAMETER GENERATION OPTIONS @@ -204,6 +213,10 @@ Generate 1024 bit DH parameters: openssl genpkey -genparam -algorithm DH -out dhp.pem \ -pkeyopt dh_paramgen_prime_len:1024 +Output RFC5114 2048 bit DH parameters with 224 bit subgroup: + + openssl genpkey -genparam -algorithm DH -out dhp.pem -pkeyopt dh_rfc5114:2 + Generate DH key from parameters: openssl genpkey -paramfile dhp.pem -out dhkey.pem