1 .\" $NetBSD: libcrypto.pl,v 1.3 2007/11/27 22:16:03 christos Exp $
3 .\" Automatically generated by Pod::Man 2.16 (Pod::Simple 3.05)
6 .\" ========================================================================
7 .de Sh \" Subsection heading
15 .de Sp \" Vertical space (when we can't use .PP)
19 .de Vb \" Begin verbatim text
24 .de Ve \" End verbatim text
28 .\" Set up some character translations and predefined strings. \*(-- will
29 .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
30 .\" double quote, and \*(R" will give a right double quote. \*(C+ will
31 .\" give a nicer C++. Capital omega is used to do unbreakable dashes and
32 .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
33 .\" nothing in troff, for use with C<>.
35 .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
39 . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
40 . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
53 .\" Escape single quotes in literal strings from groff's Unicode transform.
57 .\" If the F register is turned on, we'll generate index entries on stderr for
58 .\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index
59 .\" entries marked with X<> in POD. Of course, you'll have to process the
60 .\" output yourself in some meaningful fashion.
63 . tm Index:\\$1\t\\n%\t"\\$2"
73 .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
74 .\" Fear. Run. Save yourself. No user-serviceable parts.
75 . \" fudge factors for nroff and troff
84 . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
90 . \" simple accents for nroff and troff
100 . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
101 . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
102 . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
103 . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
104 . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
105 . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
107 . \" troff and (daisy-wheel) nroff accents
108 .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
109 .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
110 .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
111 .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
112 .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
113 .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
114 .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
115 .ds ae a\h'-(\w'a'u*4/10)'e
116 .ds Ae A\h'-(\w'A'u*4/10)'E
117 . \" corrections for vroff
118 .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
119 .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
120 . \" for low resolution devices (crt and lpr)
121 .if \n(.H>23 .if \n(.V>19 \
134 .\" ========================================================================
136 .IX Title "CRL2PKCS7 1"
137 .TH CRL2PKCS7 1 "2002-07-09" "1.1.0-dev" "OpenSSL"
138 .\" For nroff, turn off justification. Always turn off hyphenation; it makes
139 .\" way too many mistakes in technical documents.
143 crl2pkcs7 \- Create a PKCS#7 structure from a CRL and certificates.
147 .IX Header "SYNOPSIS"
148 \&\fBopenssl\fR \fBcrl2pkcs7\fR
149 [\fB\-inform PEM|DER\fR]
150 [\fB\-outform PEM|DER\fR]
151 [\fB\-in filename\fR]
152 [\fB\-out filename\fR]
153 [\fB\-certfile filename\fR]
156 .IX Header "DESCRIPTION"
157 The \fBcrl2pkcs7\fR command takes an optional \s-1CRL\s0 and one or more
158 certificates and converts them into a PKCS#7 degenerate \*(L"certificates
160 .SH "COMMAND OPTIONS"
161 .IX Header "COMMAND OPTIONS"
162 .IP "\fB\-inform DER|PEM\fR" 4
163 .IX Item "-inform DER|PEM"
164 This specifies the \s-1CRL\s0 input format. \fB\s-1DER\s0\fR format is \s-1DER\s0 encoded \s-1CRL\s0
165 structure.\fB\s-1PEM\s0\fR (the default) is a base64 encoded version of
166 the \s-1DER\s0 form with header and footer lines.
167 .IP "\fB\-outform DER|PEM\fR" 4
168 .IX Item "-outform DER|PEM"
169 This specifies the PKCS#7 structure output format. \fB\s-1DER\s0\fR format is \s-1DER\s0
170 encoded PKCS#7 structure.\fB\s-1PEM\s0\fR (the default) is a base64 encoded version of
171 the \s-1DER\s0 form with header and footer lines.
172 .IP "\fB\-in filename\fR" 4
173 .IX Item "-in filename"
174 This specifies the input filename to read a \s-1CRL\s0 from or standard input if this
175 option is not specified.
176 .IP "\fB\-out filename\fR" 4
177 .IX Item "-out filename"
178 specifies the output filename to write the PKCS#7 structure to or standard
180 .IP "\fB\-certfile filename\fR" 4
181 .IX Item "-certfile filename"
182 specifies a filename containing one or more certificates in \fB\s-1PEM\s0\fR format.
183 All certificates in the file will be added to the PKCS#7 structure. This
184 option can be used more than once to read certificates form multiple
186 .IP "\fB\-nocrl\fR" 4
188 normally a \s-1CRL\s0 is included in the output file. With this option no \s-1CRL\s0 is
189 included in the output file and a \s-1CRL\s0 is not read from the input file.
191 .IX Header "EXAMPLES"
192 Create a PKCS#7 structure from a certificate and \s-1CRL:\s0
195 \& openssl crl2pkcs7 \-in crl.pem \-certfile cert.pem \-out p7.pem
198 Creates a PKCS#7 structure in \s-1DER\s0 format with no \s-1CRL\s0 from several
199 different certificates:
202 \& openssl crl2pkcs7 \-nocrl \-certfile newcert.pem
203 \& \-certfile demoCA/cacert.pem \-outform DER \-out p7.der
207 The output file is a PKCS#7 signed data structure containing no signers and
208 just certificates and an optional \s-1CRL\s0.
210 This utility can be used to send certificates and CAs to Netscape as part of
211 the certificate enrollment process. This involves sending the \s-1DER\s0 encoded output
212 as \s-1MIME\s0 type application/x\-x509\-user\-cert.
214 The \fB\s-1PEM\s0\fR encoded form with the header and footer lines removed can be used to
215 install user certificates and CAs in \s-1MSIE\s0 using the Xenroll control.
217 .IX Header "SEE ALSO"
218 \&\fIopenssl_pkcs7\fR\|(1)