aboutsummaryrefslogtreecommitdiffstats
path: root/doc/ssl/SSL_clear.pod
diff options
context:
space:
mode:
authorLutz Jänicke <jaenicke@openssl.org>2001-02-13 14:00:09 +0000
committerLutz Jänicke <jaenicke@openssl.org>2001-02-13 14:00:09 +0000
commit8e495e4ac7caa585fe28d3e7c2fe32dd1d3e94a8 (patch)
tree9edbc9cfb312c3cd0e3875f75bdfa5171bb9c31f /doc/ssl/SSL_clear.pod
parent2afbd6fa08328c9de13bcd81776fe45ec3532b4c (diff)
downloadopenssl-8e495e4ac7caa585fe28d3e7c2fe32dd1d3e94a8.tar.gz
Finish first round of session cache documentation.
Diffstat (limited to 'doc/ssl/SSL_clear.pod')
-rw-r--r--doc/ssl/SSL_clear.pod14
1 files changed, 12 insertions, 2 deletions
diff --git a/doc/ssl/SSL_clear.pod b/doc/ssl/SSL_clear.pod
index aeb0b5c7a2..8b735d81dc 100644
--- a/doc/ssl/SSL_clear.pod
+++ b/doc/ssl/SSL_clear.pod
@@ -13,8 +13,17 @@ SSL_clear - reset SSL object to allow another connection
=head1 DESCRIPTION
Reset B<ssl> to allow another connection. All settings (method, ciphers,
-BIOs) are kept. A completely negotiated B<SSL_SESSION> is not freed but left
-untouched for the underlying B<SSL_CTX>.
+BIOs) are kept.
+
+=head1 NOTES
+
+SSL_clear is used to prepare an SSL object for a new connection. While all
+settings are kept, a side effect is the handling of the current SSL session.
+If a session is still B<open>, it is considered bad and will be removed
+from the session cache, as required by RFC2246. A session is considered open,
+if L<SSL_shutdown(3)|SSL_shutdown(3)> was not called for the connection
+or at least L<SSL_set_shutdown(3)|SSL_set_shutdown(3)> was used to
+set the SSL_SENT_SHUTDOWN state.
=head1 RETURN VALUES
@@ -34,6 +43,7 @@ The SSL_clear() operation was successful.
=back
L<SSL_new(3)|SSL_new(3)>, L<SSL_free(3)|SSL_free(3)>,
+L<SSL_shutdown(3)|SSL_shutdown(3)>, L<SSL_set_shutdown(3)|SSL_set_shutdown(3)>,
L<SSL_CTX_set_options(3)|SSL_CTX_set_options(3)>, L<ssl(3)|ssl(3)>
=cut