aboutsummaryrefslogtreecommitdiffstats
path: root/doc/manual/cli.rst
diff options
context:
space:
mode:
authorJack Lloyd <[email protected]>2018-08-23 04:21:43 -0400
committerJack Lloyd <[email protected]>2018-08-23 04:21:43 -0400
commit9a24b02e6dbff69f326a6a2a90272e238f2bb9df (patch)
treed4eeb60e98b1fecaf06a991d956a48efefebff84 /doc/manual/cli.rst
parentd71ce2f9d53557a138e5ba6d6127de952e3aa735 (diff)
Add PBES2 as alias for PBE-PKCS5v20
Easier to remember and type.
Diffstat (limited to 'doc/manual/cli.rst')
-rw-r--r--doc/manual/cli.rst6
1 files changed, 3 insertions, 3 deletions
diff --git a/doc/manual/cli.rst b/doc/manual/cli.rst
index c88e1ee90..b3379abbd 100644
--- a/doc/manual/cli.rst
+++ b/doc/manual/cli.rst
@@ -58,13 +58,13 @@ Public Key Cryptography
- For DSA *params* specifies the DSA parameters. It defaults to dsa/botan/2048.
- For EC algorithms *params* specifies the elliptic curve. It defaults to secp256r1.
- The default *pbe* algorithm is "PBE-PKCS5v20(AES-256/CBC,SHA-256)".
+ The default *pbe* algorithm is "PBES2(AES-256/CBC,SHA-256)".
- With PBE-PKCS5v20 you can select any CBC or GCM mode cipher which has an OID
+ With PBES2 scheme, you can select any CBC or GCM mode cipher which has an OID
defined (such as 3DES, Camellia, SM4, Twofish or Serpent). However most other
implementations support only AES or 3DES in CBC mode. You can also choose
Scrypt instead of PBKDF2, by using "Scrypt" instead of the name of a hash
- function, for example "PBE-PKCS5v20(AES-256/CBC,Scrypt)"
+ function, for example "PBES2(AES-256/CBC,Scrypt)"
``pkcs8 --pass-in= --pub-out --der-out --pass-out= --pbe= --pbe-millis=300 key``
Open a PKCS #8 formatted key at *key*. If *key* is encrypted, the passphrase