Skip to content

Commit a0813a9

Browse files
flichtenheldcron2
authored andcommitted
Correct documentation for --ns-cert-type
Our documentation claimed this option was removed. But it was not, for compatiblity reasons. So reflect the correct status. Change-Id: I1d1851eaebe8bf66c92dac3c8c10f68b1ec3ef33 Signed-off-by: Frank Lichtenheld <[email protected]> Acked-by: Gert Doering <[email protected]> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1428 Message-Id: <[email protected]> URL: https://www.mail-archive.com/[email protected]/msg34984.html Signed-off-by: Gert Doering <[email protected]>
1 parent 93c9b47 commit a0813a9

File tree

2 files changed

+11
-6
lines changed

2 files changed

+11
-6
lines changed

doc/man-sections/tls-options.rst

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -222,6 +222,17 @@ certificates and keys: https://github.com/OpenVPN/easy-rsa
222222
``--cert file`` above). URI is supported only when built with OpenSSL 3.0
223223
or later and any required providers are loaded. (See ``--cert`` for more details).
224224

225+
--ns-cert-type type
226+
**DEPRECATED** The ``--remote-cert-tls`` option should be used instead.
227+
The option is still available since it can't be silently ignored and needs
228+
updates to certificates and configs on both sides of the connection.
229+
However it should not be used for new clients or servers. It depends on the
230+
deprecated ``nsCertType`` certificate field.
231+
232+
Might not work depending on the TLS library used.
233+
234+
Will be removed in a future release.
235+
225236
--pkcs12 file
226237
Specify a PKCS #12 file containing local private key, local certificate,
227238
and root CA certificate. This option can be used instead of ``--ca``,

doc/man-sections/unsupported-options.rst

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -44,12 +44,6 @@ longer supported
4444
VPN tunnel security. Previously we claimed to have removed this in
4545
OpenVPN 2.5, but this wasn't actually the case.
4646

47-
--ns-cert-type
48-
Removed in OpenVPN 2.5. The ``nsCertType`` field is no longer supported
49-
in recent SSL/TLS libraries. If your certificates does not include *key
50-
usage* and *extended key usage* fields, they must be upgraded and the
51-
``--remote-cert-tls`` option should be used instead.
52-
5347
--prng
5448
Removed in OpenVPN 2.6. We now always use the PRNG of the SSL library.
5549

0 commit comments

Comments
 (0)