man: Remove keylife/rekeymargin from ipsec.conf man page

We continue to parse them but remove the documentation because mixing the two
sets of keywords in the same config might result in unexpected behavior.

References #2663.
This commit is contained in:
Tobias Brunner
2018-05-22 14:18:17 +02:00
parent b5461c63d9
commit e6d17d5613
-8
View File
@@ -538,10 +538,6 @@ The value \fB%forever\fP
means 'never give up'. means 'never give up'.
Relevant only locally, other end need not agree on it. Relevant only locally, other end need not agree on it.
.TP .TP
.B keylife
synonym for
.BR lifetime .
.TP
.BR left " = <ip address> | <fqdn> | " %any " | <range> | <subnet> " .BR left " = <ip address> | <fqdn> | " %any " | <range> | <subnet> "
The IP address of the left participant's public-network interface The IP address of the left participant's public-network interface
or one of several magic values. or one of several magic values.
@@ -1135,10 +1131,6 @@ will suppress randomization.
Relevant only locally, other end need not agree on it. Also see EXPIRY/REKEY Relevant only locally, other end need not agree on it. Also see EXPIRY/REKEY
below. below.
.TP .TP
.B rekeymargin
synonym for
.BR margintime .
.TP
.BR replay_window " = " \-1 " | <number>" .BR replay_window " = " \-1 " | <number>"
The IPsec replay window size for this connection. With the default of \-1 The IPsec replay window size for this connection. With the default of \-1
the value configured with the value configured with