diff --git a/usr.sbin/rpc.tlsservd/rpc.tlsservd.8.sav3 b/usr.sbin/rpc.tlsservd/rpc.tlsservd.8 --- a/usr.sbin/rpc.tlsservd/rpc.tlsservd.8.sav3 +++ b/usr.sbin/rpc.tlsservd/rpc.tlsservd.8 @@ -26,7 +26,7 @@ .\" $FreeBSD$ .\" .\" Modified from gssd.8 for rpc.tlsservd.8 by Rick Macklem. -.Dd January 29, 2021 +.Dd May 5, 2022 .Dt RPC.TLSSERVD 8 .Os .Sh NAME @@ -34,6 +34,7 @@ .Nd "Sun RPC over TLS Server Daemon" .Sh SYNOPSIS .Nm +.Op Fl C Ar preferred_ciphers .Op Fl D Ar certdir .Op Fl d .Op Fl h @@ -140,6 +141,21 @@ .Pp The options are as follows: .Bl -tag -width indent +.It Fl C Ar preferred_ciphers , Fl Fl ciphers= Ns Ar preferred_ciphers +Specify what preferred ciphers are to be used. +If this option is specified, +.Dq SSL_CTX_set_cipher_list() +will be called with +.Dq preferred_ciphers +as the argument. +If this option is not specified, the cipher will be chosen by +.Xr ssl 7 +and that should be adequate for most cases. +The format for the preferred cipher list is described in +.Xr openssl-ciphers 1 , +but note that many of the ciphers listed do not work for the KTLS. +At this time AES-GCM and Chacha20-poly1305 ciphers should work +for the KTLS. .It Fl D Ar certdir , Fl Fl certdir= Ns Ar certdir Use .Dq certdir @@ -322,8 +338,10 @@ .Ex -std .Sh SEE ALSO .Xr openssl 1 , +.Xr openssl-ciphers 1 , .Xr ktls 4 , .Xr exports 5 , +.Xr ssl 7 , .Xr mount_nfs 8 , .Xr nfsuserd 8 , .Xr rpc.tlsclntd 8 ,