Document that RSA public exponent must be odd
diff --git a/include/mbedtls/rsa.h b/include/mbedtls/rsa.h
index 276293c..0041dc5 100644
--- a/include/mbedtls/rsa.h
+++ b/include/mbedtls/rsa.h
@@ -433,6 +433,7 @@
  *                 This may be \c NULL if \p f_rng doesn't need a context.
  * \param nbits    The size of the public key in bits.
  * \param exponent The public exponent to use. For example, \c 65537.
+ *                 This must be odd.
  *
  * \return         \c 0 on success.
  * \return         An \c MBEDTLS_ERR_RSA_XXX error code on failure.