mirror of
https://github.com/OpenVPN/openvpn.git
synced 2024-11-23 01:34:06 +08:00
91eb4606a4
The licenses are compatible now, so we can remove the warning. Change-Id: I1879c893ed19b165fd086728fb97951eac251681 Signed-off-by: Max Fillinger <maximilian.fillinger@foxcrypto.com> Acked-by: Gert Doering <gert@greenie.muc.de> Message-Id: <20240314185527.26803-1-gert@greenie.muc.de> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg28400.html Signed-off-by: Gert Doering <gert@greenie.muc.de>
31 lines
970 B
Plaintext
31 lines
970 B
Plaintext
This version of OpenVPN has mbed TLS support. To enable, follow the
|
|
instructions below:
|
|
|
|
To build and install,
|
|
|
|
./configure --with-crypto-library=mbedtls
|
|
make
|
|
make install
|
|
|
|
This version requires mbed TLS version >= 2.0.0 or >= 3.2.1.
|
|
|
|
*************************************************************************
|
|
|
|
Due to limitations in the mbed TLS library, the following features are missing
|
|
in the mbed TLS version of OpenVPN:
|
|
|
|
* PKCS#12 file support
|
|
* --capath support - Loading certificate authorities from a directory
|
|
* Windows CryptoAPI support
|
|
* X.509 alternative username fields (must be "CN")
|
|
|
|
Plugin/Script features:
|
|
|
|
* X.509 subject line has a different format than the OpenSSL subject line
|
|
* X.509 certificate tracking
|
|
|
|
*************************************************************************
|
|
|
|
Mbed TLS 3 has implemented (parts of) the TLS 1.3 protocol, but we have disabled
|
|
support in OpenVPN because the TLS-Exporter function is not yet implemented.
|