diff --git a/docs/rolereference.rst b/docs/rolereference.rst index 721fb68288b0af95d1a0d02b1a39dd21e8f33906..ba3dcc63fd582f1a0e40affac4beaa85f499035d 100644 --- a/docs/rolereference.rst +++ b/docs/rolereference.rst @@ -757,14 +757,9 @@ Parameters **ldap_tls_ciphers** (string, optional ``NONE:+VERS-TLS1.2:+CTYPE-X509:+COMP-NULL:+SIGN-RSA-SHA256:+SIGN-RSA-SHA384:+SIGN-RSA-SHA512:+DHE-RSA:+ECDHE-RSA:+SHA256:+SHA384:+SHA512:+AEAD:+AES-128-GCM:+AES-256-GCM:+CHACHA20-POLY1305:+CURVE-ALL``) .. warning:: - Under Debian Stretch, the DHE ciphers are not usable due to a bug - present in OpenLDAP 2.4.44. See - https://bugs.launchpad.net/ubuntu/+source/openldap/+bug/1656979 - for details. DHE ciphers are usable under Debian Buster. - - It should be also noted that under Debian Buster, slapd will not - use the DH parameters generated by the role, but will instead use - them to pick one of the recommended DH parameters from `RFC-7919 + Under Debian Buster, slapd will not use the DH parameters + generated by the role, but will instead use them to pick one of + the recommended DH parameters from `RFC-7919 `_. This is based on the size of role-generated parameters.