1 .\" $NetBSD: openssl_crl.1,v 1.14 2015/06/12 17:01:14 christos Exp $
3 .\" Automatically generated by Pod::Man 2.28 (Pod::Simple 3.28)
6 .\" ========================================================================
7 .de Sp \" Vertical space (when we can't use .PP)
11 .de Vb \" Begin verbatim text
16 .de Ve \" End verbatim text
20 .\" Set up some character translations and predefined strings. \*(-- will
21 .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
22 .\" double quote, and \*(R" will give a right double quote. \*(C+ will
23 .\" give a nicer C++. Capital omega is used to do unbreakable dashes and
24 .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
25 .\" nothing in troff, for use with C<>.
27 .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
31 . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
32 . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
47 .\" Escape single quotes in literal strings from groff's Unicode transform.
51 .\" If the F register is turned on, we'll generate index entries on stderr for
52 .\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
53 .\" entries marked with X<> in POD. Of course, you'll have to process the
54 .\" output yourself in some meaningful fashion.
56 .\" Avoid warning from groff about undefined register 'F'.
60 .if \n(.g .if rF .nr rF 1
61 .if (\n(rF:(\n(.g==0)) \{
64 . tm Index:\\$1\t\\n%\t"\\$2"
74 .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
75 .\" Fear. Run. Save yourself. No user-serviceable parts.
76 . \" fudge factors for nroff and troff
85 . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
91 . \" simple accents for nroff and troff
101 . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
102 . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
103 . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
104 . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
105 . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
106 . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
108 . \" troff and (daisy-wheel) nroff accents
109 .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
110 .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
111 .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
112 .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
113 .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
114 .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
115 .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
116 .ds ae a\h'-(\w'a'u*4/10)'e
117 .ds Ae A\h'-(\w'A'u*4/10)'E
118 . \" corrections for vroff
119 .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
120 .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
121 . \" for low resolution devices (crt and lpr)
122 .if \n(.H>23 .if \n(.V>19 \
135 .\" ========================================================================
138 .TH CRL 1 "2014-08-10" "1.0.1n" "OpenSSL"
139 .\" For nroff, turn off justification. Always turn off hyphenation; it makes
140 .\" way too many mistakes in technical documents.
148 .IX Header "SYNOPSIS"
149 \&\fBopenssl\fR \fBcrl\fR
150 [\fB\-inform PEM|DER\fR]
151 [\fB\-outform PEM|DER\fR]
153 [\fB\-in filename\fR]
154 [\fB\-out filename\fR]
155 [\fB\-nameopt option\fR]
161 [\fB\-CAfile file\fR]
164 .IX Header "DESCRIPTION"
165 The \fBcrl\fR command processes \s-1CRL\s0 files in \s-1DER\s0 or \s-1PEM\s0 format.
166 .SH "COMMAND OPTIONS"
167 .IX Header "COMMAND OPTIONS"
168 .IP "\fB\-inform DER|PEM\fR" 4
169 .IX Item "-inform DER|PEM"
170 This specifies the input format. \fB\s-1DER\s0\fR format is \s-1DER\s0 encoded \s-1CRL\s0
171 structure. \fB\s-1PEM\s0\fR (the default) is a base64 encoded version of
172 the \s-1DER\s0 form with header and footer lines.
173 .IP "\fB\-outform DER|PEM\fR" 4
174 .IX Item "-outform DER|PEM"
175 This specifies the output format, the options have the same meaning as the
176 \&\fB\-inform\fR option.
177 .IP "\fB\-in filename\fR" 4
178 .IX Item "-in filename"
179 This specifies the input filename to read from or standard input if this
180 option is not specified.
181 .IP "\fB\-out filename\fR" 4
182 .IX Item "-out filename"
183 specifies the output filename to write to or standard output by
187 print out the \s-1CRL\s0 in text form.
188 .IP "\fB\-nameopt option\fR" 4
189 .IX Item "-nameopt option"
190 option which determines how the subject or issuer names are displayed. See
191 the description of \fB\-nameopt\fR in \fIopenssl_x509\fR\|(1).
192 .IP "\fB\-noout\fR" 4
194 don't output the encoded version of the \s-1CRL.\s0
197 output a hash of the issuer name. This can be use to lookup CRLs in
198 a directory by issuer name.
199 .IP "\fB\-hash_old\fR" 4
201 outputs the \*(L"hash\*(R" of the \s-1CRL\s0 issuer name using the older algorithm
202 as used by OpenSSL versions before 1.0.0.
203 .IP "\fB\-issuer\fR" 4
205 output the issuer name.
206 .IP "\fB\-lastupdate\fR" 4
207 .IX Item "-lastupdate"
208 output the lastUpdate field.
209 .IP "\fB\-nextupdate\fR" 4
210 .IX Item "-nextupdate"
211 output the nextUpdate field.
212 .IP "\fB\-CAfile file\fR" 4
213 .IX Item "-CAfile file"
214 verify the signature on a \s-1CRL\s0 by looking up the issuing certificate in
216 .IP "\fB\-CApath dir\fR" 4
217 .IX Item "-CApath dir"
218 verify the signature on a \s-1CRL\s0 by looking up the issuing certificate in
219 \&\fBdir\fR. This directory must be a standard certificate directory: that
220 is a hash of each subject name (using \fBx509 \-hash\fR) should be linked
224 The \s-1PEM CRL\s0 format uses the header and footer lines:
227 \& \-\-\-\-\-BEGIN X509 CRL\-\-\-\-\-
228 \& \-\-\-\-\-END X509 CRL\-\-\-\-\-
231 .IX Header "EXAMPLES"
232 Convert a \s-1CRL\s0 file from \s-1PEM\s0 to \s-1DER:\s0
235 \& openssl crl \-in crl.pem \-outform DER \-out crl.der
238 Output the text form of a \s-1DER\s0 encoded certificate:
241 \& openssl crl \-in crl.der \-text \-noout
245 Ideally it should be possible to create a \s-1CRL\s0 using appropriate options
248 .IX Header "SEE ALSO"
249 \&\fIopenssl_crl2pkcs7\fR\|(1), \fIopenssl_ca\fR\|(1), \fIopenssl_x509\fR\|(1)