From 3aba6b86a127954fdcd1c1c51ce66b5731176e50 Mon Sep 17 00:00:00 2001 From: Eric Wong Date: Mon, 29 Feb 2016 02:05:35 +0000 Subject: document SSL::SSL::SSLContext#set_params use I use whatever Ruby developers deem to be reasonable defaults. Because compatibility with old systems is still valued, these may not be the safest possible configuration; but ought to be better than what OpenSSL upstream provides by default. --- Documentation/yahns_config.pod | 1 + 1 file changed, 1 insertion(+) (limited to 'Documentation') diff --git a/Documentation/yahns_config.pod b/Documentation/yahns_config.pod index 3b1f2e4..aadd691 100644 --- a/Documentation/yahns_config.pod +++ b/Documentation/yahns_config.pod @@ -446,6 +446,7 @@ An example which seems to work is: ssl_ctx.key = OpenSSL::PKey::RSA.new( IO.read('/etc/ssl/private/example.key') ) + ssl_ctx.set_params # use defaults provided by Ruby on top of OpenSSL app(:rack, "/path/to/my/app/config.ru") do listen 443, ssl_ctx: ssl_ctx -- cgit v1.2.3-24-ge0c7