doc: Update documentation of SSL_CTX_set_dh_auto()

Update the documentation of the dh_tmp_auto argument in
regards to its behavior when the argument value is 2.

Fixes #27606

Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/28366)
This commit is contained in:
Ryan Hooper 2025-08-28 09:12:39 -04:00 committed by Tomas Mraz
parent 56ce30abb7
commit 7600608eab
1 changed files with 5 additions and 3 deletions

View File

@ -58,9 +58,11 @@ the actual key is newly generated during the negotiation.
Typically applications should use well known DH parameters that have built-in
support in OpenSSL. The macros SSL_CTX_set_dh_auto() and SSL_set_dh_auto()
configure OpenSSL to use the default built-in DH parameters for the B<SSL_CTX>
and B<SSL> objects respectively. Passing a value of 1 in the I<onoff> parameter
switches the feature on, and passing a value of 0 switches it off. The default
setting is off.
and B<SSL> objects respectively. Passing a value of 2 or 1 in the I<onoff>
parameter switches it on. If the I<onoff> parameter is set to 2, it will force
the DH key size to 1024 if the B<SSL_CTX> or B<SSL> security level
L<SSL_CTX_set_security_level(3)> is 0 or 1. Passing a value of 0 switches
it off. The default setting is off.
If "auto" DH parameters are switched on then the parameters will be selected to
be consistent with the size of the key associated with the server's certificate.