diff options
author | Matt Caswell <matt@openssl.org> | 2020-10-23 17:44:35 +0200 |
---|---|---|
committer | Matt Caswell <matt@openssl.org> | 2020-11-18 15:14:53 +0100 |
commit | 1b2a55ffa2e6acde6fb9909276936cc1c61c89b1 (patch) | |
tree | aa34691ce43e062d427f8640870ad02c4db5314c /CHANGES.md | |
parent | Add a test for the various ways of setting temporary DH params (diff) | |
download | openssl-1b2a55ffa2e6acde6fb9909276936cc1c61c89b1.tar.xz openssl-1b2a55ffa2e6acde6fb9909276936cc1c61c89b1.zip |
Add a CHANGES.md entry for the "tmp_dh" functions/macros
Describe the tmp_dh deprecations, and what applications should do instead.
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/13368)
Diffstat (limited to 'CHANGES.md')
-rw-r--r-- | CHANGES.md | 15 |
1 files changed, 15 insertions, 0 deletions
diff --git a/CHANGES.md b/CHANGES.md index 6e275f1d73..ca4e096ed2 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -23,6 +23,21 @@ OpenSSL 3.0 ### Changes between 1.1.1 and 3.0 [xx XXX xxxx] + * The functions SSL_CTX_set_tmp_dh_callback and SSL_set_tmp_dh_callback, as + well as the macros SSL_CTX_set_tmp_dh() and SSL_set_tmp_dh() have been + deprecated. These are used to set the Diffie-Hellman (DH) parameters that + are to be used by servers requiring ephemeral DH keys. Instead applications + should consider using the built-in DH parameters that are available by + calling SSL_CTX_set_dh_auto() or SSL_set_dh_auto(). If custom parameters are + necessary then applications can use the alternative functions + SSL_CTX_set0_tmp_dh_pkey() and SSL_set0_tmp_dh_pkey(). There is no direct + replacement for the "callback" functions. The callback was originally useful + in order to have different parameters for export and non-export ciphersuites. + Export ciphersuites are no longer supported by OpenSSL. Use of the callback + functions should be replaced by one of the other methods described above. + + *Matt Caswell* + * The -crypt option to the passwd command line tool has been removed. *Paul Dale* |