|
X.509 certificate
support. No v3 extensions are supported. |
|
Self-signed v1
certificates can be generated given a private
key. |
|
PEM private keys can be
decrypted with AES128 or AES256 ciphers. |
|
Server peer verification
(can choose between automatic verification, or
verification after the handshake). |
|
Client peer verification
on the server (handshake is terminated
immediately on failure). |
|
Certificate chaining -
the number of certificates is compile- time
configurable individually on both client/server. |
|
CA certificate store size
is compile-time configurable. |
|
PKCS#8, PKCS#12
key/certificates supported (PBE-SHA1-RC4-128
encryption only, with a single key). |