from small one page howto to huge articles all in one place
 

search text in:





Poll
What does your sytem tell when running "ulimit -u"?








poll results

Last additions:
using iotop to find disk usage hogs

using iotop to find disk usage hogs

words:

887

views:

20152

userrating:

average rating: 3.4 (203 votes) (1=very good 6=terrible)


May 25th. 2007:
Words

486

Views

35930

why adblockers are bad


Workaround and fixes for the current Core Dump Handling vulnerability affected kernels

Workaround and fixes for the current Core Dump Handling vulnerability affected kernels

words:

161

views:

20945

userrating:

average rating: 1.0 (50 votes) (1=very good 6=terrible)


April, 26th. 2006:

Druckversion
You are here: manpages





certtool

Section: User Commands (1)
Updated: May 23rd 2005
Index Return to Main Contents
 

NAME

certtool - Manipulate certificates and keys.  

SYNOPSIS

certtool [options]  

DESCRIPTION

Generate X.509 certificates, certificate requests, and private keys.  

OPTIONS

 

Program control options

-d, --debug LEVEL
Specify the debug level. Default is 1.
-h, --help
Shows this help text
-v, --version
Shows the program's version

 

Getting information on X.509 certificates

-i, --certificate-info
Print information on a certificate.
-k, --key-info
Print information on a private key.
-l, --crl-info
Print information on a CRL.
--p12-info
Print information on a PKCS #12 structure.

 

Getting information on Openpgp certificates

--pgp--certificate-info
Print information on an OpenPGP certificate.
--pgp--key-info
Print information on an OpenPGP private key.
--pgp--ring-info
Print information on a keyring.

 

Generating/verifying X.509 certificates/keys

-c, --generate-certificate
Generate a signed certificate.
-e, --verify-chain
Verify a PEM encoded certificate chain. The last certificate in the chain must be a self signed one.
--generate-dh-params
Generate PKCS #3 encoded Diffie-Hellman parameters.
--load-ca-certificate FILE
Certificate authority's certificate file to use.
--load-ca-privkey FILE
Certificate authority's private key file to use.
--load-certificate FILE
Certificate file to use.
--load-privkey FILE
Private key file to use.
--load-request FILE
Certificate request file to use.
-p, --generate-privkey
Generate a private key.
-q, --generate-request
Generate a PKCS #10 certificate request.
-s, --generate-self-signed
Generate a self-signed certificate.
-u, --update-certificate
Update a signed certificate.

 

Controlling output

-8, --pkcs8
Use PKCS #8 format for private keys.
--pkcs-cipher
The cipher to use when doing pkcs encryption. Valid options are 3des,aes-128,aes-192,aes-256,rc2-40
--dsa
Generate a DSA key.
--bits BITS
Specify the number of bits for key generation.
--export-ciphers
Use weak encryption algorithms.
--inraw
Use RAW/DER format for input certificates and private keys.
--infile FILE
Input file.
--outraw
Use RAW/DER format for output certificates and private keys.
--outfile FILE
Output file.
--password PASSWORD
Password to use.
--to-p12
Generate a PKCS #12 structure.
--template
Use a template file to read input. See the doc/certtool.cfg in the distribution, for an example.
--fix-key
Some previous versions of certtool generated wrongly the optional parameters in a private key. This may affect programs that used them. To fix an old private key use --key-info in combination with this parameter.
--v1
When generating a certificate use the X.509 version 1 format. This does not add any extensions (such as indication for a CA) but some programs do need these.

 

EXAMPLES

To create a private key, run:

$ certtool --generate-privkey --outfile key.pem

To create a certificate request (needed when the certificate is issued by another party), run:

$ certtool --generate-request --load-privkey key.pem \
   --outfile request.pem

To generate a certificate using the previous request, use the command:

$ certtool --generate-certificate --load-request request.pem \
   --outfile cert.pem --load-ca-certificate ca-cert.pem \
   --load-ca-privkey ca-key.pem

To generate a certificate using the private key only, use the command:

$ certtool --generate-certificate --load-privkey key.pem \
   --outfile cert.pem --load-ca-certificate ca-cert.pem \
   --load-ca-privkey ca-key.pem

To view the certificate information, use:

$ certtool --certificate-info --infile cert.pem

To generate a PKCS #12 structure using the previous key and certificate, use the command:

$ certtool --load-certificate cert.pem --load-privkey key.pem \
   --to-p12 --outder --outfile key.p12

 

AUTHOR

Nikos Mavroyanopoulos <nmav@gnutls.org> and others; see /usr/share/doc/gnutls-bin/AUTHORS for a complete list.

This manual page was written by Ivo Timmermans <ivo@debian.org>, for the Debian GNU/Linux system (but may be used by others).


 

Index

NAME
SYNOPSIS
DESCRIPTION
OPTIONS
Program control options
Getting information on X.509 certificates
Getting information on Openpgp certificates
Generating/verifying X.509 certificates/keys
Controlling output
EXAMPLES
AUTHOR

Please read "Why adblockers are badwww.cars2fast4u.de



Other free services
toURL.org
Shorten long
URLs to short
links like
http://tourl.org/2
tourl.org
.
FeedCollector
Combine various newsfeeds to one customized webpage
www.feedcollector.org
.
Reverse DNS lookup
Find out which hostname(s)
resolve to a
given IP or other hostnames for the server
www.reversednslookup.org
rdf newsfeed | rss newsfeed | Atom newsfeed
- Powered by LeopardCMS - Running on Gentoo -
Copyright 2004-2011 S&P Softwaredesign
Valid XHTML1.1 : Valid CSS : buttonmaker
- Level Triple-A Conformance to Web Content Accessibility Guidelines 1.0 -
- Copyright and legal notices -
Time to create this page: 40.0 ms
system status display