3d9ebc373f
Use new SSL_CONF options in demo. Add intermediate and root CAs and update all to use SHA256. Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
19 lines
456 B
INI
19 lines
456 B
INI
# Example configuration file
|
|
# Port to listen on
|
|
Port = 4433
|
|
# Disable TLS v1.2 for test.
|
|
# Protocol = ALL, -TLSv1.2
|
|
# Only support 3 curves
|
|
Curves = P-521:P-384:P-256
|
|
# Automatic curve selection
|
|
ECDHParameters = Automatic
|
|
# Restricted signature algorithms
|
|
SignatureAlgorithms = RSA+SHA512:ECDSA+SHA512
|
|
Certificate=server.pem
|
|
PrivateKey=server.pem
|
|
ChainCAFile=root.pem
|
|
VerifyCAFile=root.pem
|
|
|
|
# Request certificate
|
|
VerifyMode=Request
|
|
ClientCAFile=root.pem
|