From f2e2cce2aad63e76643507c87d67e95367fdfdf9 Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Thu, 29 Jan 2015 11:41:08 +0100 Subject: [PATCH] man: Describe trust chain constraints configuration for EAP methods --- man/ipsec.conf.5.in | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/man/ipsec.conf.5.in b/man/ipsec.conf.5.in index 851bd1750..696c6a12f 100644 --- a/man/ipsec.conf.5.in +++ b/man/ipsec.conf.5.in @@ -614,7 +614,9 @@ Alternatively, IANA assigned EAP method numbers are accepted. Vendor specific EAP methods are defined in the form .B eap-type-vendor .RB "(e.g. " eap-7-12345 ). -For +To specify signature and trust chain constraints for EAP-(T)TLS, append a colon +to the EAP method, followed by the key type/size and hash algorithm as discussed +above. For .B xauth, an XAuth authentication backend can be specified, such as .B xauth-generic