diff --git a/docs/manual/mod/quickreference.html.de b/docs/manual/mod/quickreference.html.de
index fffcf13286..9953bb34f8 100644
--- a/docs/manual/mod/quickreference.html.de
+++ b/docs/manual/mod/quickreference.html.de
@@ -990,6 +990,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.en b/docs/manual/mod/quickreference.html.en
index 9e34740b9f..0bf05c591e 100644
--- a/docs/manual/mod/quickreference.html.en
+++ b/docs/manual/mod/quickreference.html.en
@@ -975,6 +975,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.es b/docs/manual/mod/quickreference.html.es
index 27ce21c964..f413ed181d 100644
--- a/docs/manual/mod/quickreference.html.es
+++ b/docs/manual/mod/quickreference.html.es
@@ -982,6 +982,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.ja.utf8 b/docs/manual/mod/quickreference.html.ja.utf8
index 3eeb6a1a6e..31aebea1a9 100644
--- a/docs/manual/mod/quickreference.html.ja.utf8
+++ b/docs/manual/mod/quickreference.html.ja.utf8
@@ -913,6 +913,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.ko.euc-kr b/docs/manual/mod/quickreference.html.ko.euc-kr
index 38ae299519..defa19e264 100644
--- a/docs/manual/mod/quickreference.html.ko.euc-kr
+++ b/docs/manual/mod/quickreference.html.ko.euc-kr
@@ -937,6 +937,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.tr.utf8 b/docs/manual/mod/quickreference.html.tr.utf8
index ca2d97db15..002e8565dd 100644
--- a/docs/manual/mod/quickreference.html.tr.utf8
+++ b/docs/manual/mod/quickreference.html.tr.utf8
@@ -972,6 +972,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sk | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sk | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sk | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sk | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sk | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sk | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/mod/quickreference.html.zh-cn b/docs/manual/mod/quickreference.html.zh-cn
index 98be66315c..26f158bc8c 100644
--- a/docs/manual/mod/quickreference.html.zh-cn
+++ b/docs/manual/mod/quickreference.html.zh-cn
@@ -970,6 +970,8 @@ Cache
SSLSessionCacheTimeout seconds | 300 | sv | E |
Number of seconds before an SSL session expires
in the Session Cache |
SSLSessionTicketKeyFile file-path | | sv | E |
Persistent encryption/decryption key for TLS session tickets |
+
SSLSRPUnknownUserSeed secret-string | | sv | E |
SRP unknown user seed |
+
SSLSRPVerifierFile file-path | | sv | E |
Path to SRP verifier file |
SSLStaplingCache type | | s | E |
Configures the OCSP stapling cache |
SSLStaplingErrorCacheTimeout seconds | 600 | sv | E |
Number of seconds before expiring invalid responses in the OCSP stapling cache |
SSLStaplingFakeTryLater on|off | on | sv | E |
Synthesize "tryLater" responses for failed OCSP stapling queries |
diff --git a/docs/manual/ssl/ssl_faq.html.en b/docs/manual/ssl/ssl_faq.html.en
index 0ccebfb2a2..4793ca4926 100644
--- a/docs/manual/ssl/ssl_faq.html.en
+++ b/docs/manual/ssl/ssl_faq.html.en
@@ -725,6 +725,27 @@ SetEnvIf User-Agent "MSIE [2-5]" \
or otherwise.
+
+
TLS-SRP (Secure Remote Password key exchange for TLS, specified in RFC 5054)
+ can supplement or replace certificates in authenticating an SSL connection.
+ To use TLS-SRP, set the
+ SSLSRPVerifierFile
directive to
+ point to an OpenSSL SRP verifier file. To create the verifier file, use the
+ openssl
tool:
+
+ openssl srp -srpvfile passwd.srpv -add username
+
+
After creating this file, specify it in the SSL server configuration:
+
+ SSLSRPVerifierFile /path/to/passwd.srpv
+
+
To force clients to use non-certificate TLS-SRP cipher suites, use the
+ following directive:
+
+ SSLCipherSuite "!DSS:!aRSA:SRP"
+
+
+
Cette traduction peut être périmée. Vérifiez la version
+ anglaise pour les changements récents.