From 618eb125f01c64640ff86f343c9dc1d037499175 Mon Sep 17 00:00:00 2001 From: "Dr. Stephen Henson" Date: Wed, 7 Dec 2011 00:42:22 +0000 Subject: [PATCH] Document RFC5114 "generation" options. --- doc/apps/genpkey.pod | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/doc/apps/genpkey.pod b/doc/apps/genpkey.pod index 1611b5ca78..84f9edb2d7 100644 --- a/doc/apps/genpkey.pod +++ b/doc/apps/genpkey.pod @@ -126,6 +126,15 @@ The number of bits in the prime parameter B

. The value to use for the generator B. +=item B + +If this option is set then the appropriate RFC5114 parameters are used +instead of generating new parameters. The value B can take the +values 1, 2 or 3 corresponding to RFC5114 DH parameters consisting of +1024 bit group with 160 bit subgroup, 2048 bit group with 224 bit subgroup +and 2048 bit group with 256 bit subgroup as mentioned in RFC5114 sections +2.1, 2.2 and 2.3 respectively. + =back =head1 EC PARAMETER GENERATION OPTIONS @@ -204,6 +213,10 @@ Generate 1024 bit DH parameters: openssl genpkey -genparam -algorithm DH -out dhp.pem \ -pkeyopt dh_paramgen_prime_len:1024 +Output RFC5114 2048 bit DH parameters with 224 bit subgroup: + + openssl genpkey -genparam -algorithm DH -out dhp.pem -pkeyopt dh_rfc5114:2 + Generate DH key from parameters: openssl genpkey -paramfile dhp.pem -out dhkey.pem -- 2.25.1