Commit e2ce2112 authored by Manuel Pégourié-Gonnard's avatar Manuel Pégourié-Gonnard
Browse files

Update doc of ssl_set_authmode()

parent bb4dd370
...@@ -869,6 +869,12 @@ void ssl_set_endpoint( ssl_context *ssl, int endpoint ); ...@@ -869,6 +869,12 @@ void ssl_set_endpoint( ssl_context *ssl, int endpoint );
* *
* SSL_VERIFY_REQUIRED: peer *must* present a valid certificate, * SSL_VERIFY_REQUIRED: peer *must* present a valid certificate,
* handshake is aborted if verification failed. * handshake is aborted if verification failed.
*
* \note On client, SSL_VERIFY_REQUIRED is the recommended mode.
* With SSL_VERIFY_OPTIONAL, the user needs to call ssl_get_verify_result() at
* the right time(s), which may not be obvious, while REQUIRED always perform
* the verification as soon as possible. For example, REQUIRED was protecting
* against the "triple handshake" attack even before it was found.
*/ */
void ssl_set_authmode( ssl_context *ssl, int authmode ); void ssl_set_authmode( ssl_context *ssl, int authmode );
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment