Document more precisely what goes into the default preset

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
This commit is contained in:
Gilles Peskine 2021-06-07 21:26:41 +02:00
parent 0ecd719edf
commit 646b78b927

View file

@ -2987,7 +2987,7 @@ void mbedtls_ssl_conf_dhm_min_bitlen( mbedtls_ssl_config *conf,
#if defined(MBEDTLS_ECP_C) #if defined(MBEDTLS_ECP_C)
/** /**
* \brief Set the allowed curves in order of preference. * \brief Set the allowed curves in order of preference.
* (Default: all defined curves.) * (Default: all defined curves in order of decreasing size.)
* *
* On server: this only affects selection of the ECDHE curve; * On server: this only affects selection of the ECDHE curve;
* the curves used for ECDH and ECDSA are determined by the * the curves used for ECDH and ECDSA are determined by the
@ -3019,7 +3019,7 @@ void mbedtls_ssl_conf_curves( mbedtls_ssl_config *conf,
#if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED) #if defined(MBEDTLS_KEY_EXCHANGE_WITH_CERT_ENABLED)
/** /**
* \brief Set the allowed hashes for signatures during the handshake. * \brief Set the allowed hashes for signatures during the handshake.
* (Default: all available hashes except MD5.) * (Default: all SHA2 hashes, largest first.)
* *
* \note This only affects which hashes are offered and can be used * \note This only affects which hashes are offered and can be used
* for signatures during the handshake. Hashes for message * for signatures during the handshake. Hashes for message