0
0
mirror of https://github.com/OpenVPN/openvpn.git synced 2024-09-20 12:02:28 +02:00

Add note about file permissions and --crl-verify to manpage.

Trac #522

Signed-off-by: Gert Doering <gert@greenie.muc.de>
Acked-by: Steffan Karger <steffan.karger@fox-it.com>
Message-Id: <1430593625-855-1-git-send-email-gert@greenie.muc.de>
URL: http://article.gmane.org/gmane.network.openvpn.devel/9634
This commit is contained in:
Gert Doering 2015-05-02 21:07:05 +02:00
parent e473b7c4ce
commit d55be0fb80

View File

@ -5068,6 +5068,11 @@ is a directory containing files named as revoked serial numbers
requests a connection, where the client certificate serial number
(decimal string) is the name of a file present in the directory,
it will be rejected.
Note: As the crl file (or directory) is read every time a peer connects,
if you are dropping root privileges with
.B --user,
make sure that this user has sufficient privileges to read the file.
.\"*********************************************************
.SS SSL Library information:
.\"*********************************************************