mirror of
https://github.com/asterisk/asterisk.git
synced 2025-11-20 16:50:14 +00:00
pjsip: clarify tls cert and key file usage
A question arose as to whether a .pem file could be provided in place of the .crt and .key files in a PJSIP TLS configuration. I tested this and discovered that although a cert will be read from the pem file, a key will not, and thus the priv_key_file entry is still required. This update to the fine documentation clarifies the option usage. AST-1448 #close Review: https://reviewboard.asterisk.org/r/4129/ Reported by: John Bigelow ........ Merged revisions 426928 from http://svn.asterisk.org/svn/asterisk/branches/12 git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/13@426930 65c4cc65-6c06-0410-ace0-fbb531ad65f3
This commit is contained in:
@@ -747,7 +747,10 @@
|
|||||||
; "")
|
; "")
|
||||||
;ca_list_file= ; File containing a list of certificates to read TLS ONLY
|
;ca_list_file= ; File containing a list of certificates to read TLS ONLY
|
||||||
; (default: "")
|
; (default: "")
|
||||||
;cert_file= ; Certificate file for endpoint TLS ONLY (default: "")
|
;cert_file= ; Certificate file for endpoint TLS ONLY
|
||||||
|
; Will read .crt or .pem file but only uses cert,
|
||||||
|
; a .key file must be specified via priv_key_file
|
||||||
|
; (default: "")
|
||||||
;cipher= ; Preferred cryptography cipher names TLS ONLY (default: "")
|
;cipher= ; Preferred cryptography cipher names TLS ONLY (default: "")
|
||||||
;domain= ; Domain the transport comes from (default: "")
|
;domain= ; Domain the transport comes from (default: "")
|
||||||
;external_media_address= ; External IP address to use in RTP handling
|
;external_media_address= ; External IP address to use in RTP handling
|
||||||
|
|||||||
@@ -817,6 +817,12 @@
|
|||||||
</configOption>
|
</configOption>
|
||||||
<configOption name="cert_file">
|
<configOption name="cert_file">
|
||||||
<synopsis>Certificate file for endpoint (TLS ONLY)</synopsis>
|
<synopsis>Certificate file for endpoint (TLS ONLY)</synopsis>
|
||||||
|
<description><para>
|
||||||
|
A path to a .crt or .pem file can be provided. However, only
|
||||||
|
the certificate is read from the file, not the private key.
|
||||||
|
The <literal>priv_key_file</literal> option must supply a
|
||||||
|
matching key file.
|
||||||
|
</para></description>
|
||||||
</configOption>
|
</configOption>
|
||||||
<configOption name="cipher">
|
<configOption name="cipher">
|
||||||
<synopsis>Preferred cryptography cipher names (TLS ONLY)</synopsis>
|
<synopsis>Preferred cryptography cipher names (TLS ONLY)</synopsis>
|
||||||
|
|||||||
Reference in New Issue
Block a user