man: Remove keylife/rekeymargin from ipsec.conf man page
We continue to parse them but remove the documentation because mixing the two sets of keywords in the same config might result in unexpected behavior. References #2663.
This commit is contained in:
parent
b5461c63d9
commit
e6d17d5613
|
@ -538,10 +538,6 @@ The value \fB%forever\fP
|
|||
means 'never give up'.
|
||||
Relevant only locally, other end need not agree on it.
|
||||
.TP
|
||||
.B keylife
|
||||
synonym for
|
||||
.BR lifetime .
|
||||
.TP
|
||||
.BR left " = <ip address> | <fqdn> | " %any " | <range> | <subnet> "
|
||||
The IP address of the left participant's public-network interface
|
||||
or one of several magic values.
|
||||
|
@ -1135,10 +1131,6 @@ will suppress randomization.
|
|||
Relevant only locally, other end need not agree on it. Also see EXPIRY/REKEY
|
||||
below.
|
||||
.TP
|
||||
.B rekeymargin
|
||||
synonym for
|
||||
.BR margintime .
|
||||
.TP
|
||||
.BR replay_window " = " \-1 " | <number>"
|
||||
The IPsec replay window size for this connection. With the default of \-1
|
||||
the value configured with
|
||||
|
|
Loading…
Reference in New Issue