f4401cd869
alter des.h to be friendly with openssl/des.h (you can include both in the same file) make libkrb to depend on libdes. bump major. massage various portioin of heimdal to be friendly with openssl 0.9.7b.
242 lines
6.6 KiB
Groff
242 lines
6.6 KiB
Groff
.\" $NetBSD: openssl_crl.1,v 1.10 2003/07/24 14:16:50 itojun Exp $
|
|
.\"
|
|
.\" Automatically generated by Pod::Man version 1.02
|
|
.\" Thu Jul 24 13:07:42 2003
|
|
.\"
|
|
.\" Standard preamble:
|
|
.\" ======================================================================
|
|
.de Sh \" Subsection heading
|
|
.br
|
|
.if t .Sp
|
|
.ne 5
|
|
.PP
|
|
\fB\\$1\fR
|
|
.PP
|
|
..
|
|
.de Sp \" Vertical space (when we can't use .PP)
|
|
.if t .sp .5v
|
|
.if n .sp
|
|
..
|
|
.de Ip \" List item
|
|
.br
|
|
.ie \\n(.$>=3 .ne \\$3
|
|
.el .ne 3
|
|
.IP "\\$1" \\$2
|
|
..
|
|
.de Vb \" Begin verbatim text
|
|
.ft CW
|
|
.nf
|
|
.ne \\$1
|
|
..
|
|
.de Ve \" End verbatim text
|
|
.ft R
|
|
|
|
.fi
|
|
..
|
|
.\" Set up some character translations and predefined strings. \*(-- will
|
|
.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
|
|
.\" double quote, and \*(R" will give a right double quote. | will give a
|
|
.\" real vertical bar. \*(C+ will give a nicer C++. Capital omega is used
|
|
.\" to do unbreakable dashes and therefore won't be available. \*(C` and
|
|
.\" \*(C' expand to `' in nroff, nothing in troff, for use with C<>
|
|
.tr \(*W-|\(bv\*(Tr
|
|
.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
|
|
.ie n \{\
|
|
. ds -- \(*W-
|
|
. ds PI pi
|
|
. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
|
|
. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
|
|
. ds L" ""
|
|
. ds R" ""
|
|
. ds C` `
|
|
. ds C' '
|
|
'br\}
|
|
.el\{\
|
|
. ds -- \|\(em\|
|
|
. ds PI \(*p
|
|
. ds L" ``
|
|
. ds R" ''
|
|
'br\}
|
|
.\"
|
|
.\" If the F register is turned on, we'll generate index entries on stderr
|
|
.\" for titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and
|
|
.\" index entries marked with X<> in POD. Of course, you'll have to process
|
|
.\" the output yourself in some meaningful fashion.
|
|
.if \nF \{\
|
|
. de IX
|
|
. tm Index:\\$1\t\\n%\t"\\$2"
|
|
. .
|
|
. nr % 0
|
|
. rr F
|
|
.\}
|
|
.\"
|
|
.\" For nroff, turn off justification. Always turn off hyphenation; it
|
|
.\" makes way too many mistakes in technical documents.
|
|
.hy 0
|
|
.if n .na
|
|
.\"
|
|
.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
|
|
.\" Fear. Run. Save yourself. No user-serviceable parts.
|
|
.bd B 3
|
|
. \" fudge factors for nroff and troff
|
|
.if n \{\
|
|
. ds #H 0
|
|
. ds #V .8m
|
|
. ds #F .3m
|
|
. ds #[ \f1
|
|
. ds #] \fP
|
|
.\}
|
|
.if t \{\
|
|
. ds #H ((1u-(\\\\n(.fu%2u))*.13m)
|
|
. ds #V .6m
|
|
. ds #F 0
|
|
. ds #[ \&
|
|
. ds #] \&
|
|
.\}
|
|
. \" simple accents for nroff and troff
|
|
.if n \{\
|
|
. ds ' \&
|
|
. ds ` \&
|
|
. ds ^ \&
|
|
. ds , \&
|
|
. ds ~ ~
|
|
. ds /
|
|
.\}
|
|
.if t \{\
|
|
. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
|
|
. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
|
|
. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
|
|
. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
|
|
. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
|
|
. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
|
|
.\}
|
|
. \" troff and (daisy-wheel) nroff accents
|
|
.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
|
|
.ds 8 \h'\*(#H'\(*b\h'-\*(#H'
|
|
.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
|
|
.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
|
|
.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
|
|
.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
|
|
.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
|
|
.ds ae a\h'-(\w'a'u*4/10)'e
|
|
.ds Ae A\h'-(\w'A'u*4/10)'E
|
|
. \" corrections for vroff
|
|
.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
|
|
.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
|
|
. \" for low resolution devices (crt and lpr)
|
|
.if \n(.H>23 .if \n(.V>19 \
|
|
\{\
|
|
. ds : e
|
|
. ds 8 ss
|
|
. ds o a
|
|
. ds d- d\h'-1'\(ga
|
|
. ds D- D\h'-1'\(hy
|
|
. ds th \o'bp'
|
|
. ds Th \o'LP'
|
|
. ds ae ae
|
|
. ds Ae AE
|
|
.\}
|
|
.rm #[ #] #H #V #F C
|
|
.\" ======================================================================
|
|
.\"
|
|
.IX Title "CRL 1"
|
|
.TH CRL 1 "0.9.7b" "2000-02-08" "OpenSSL"
|
|
.UC
|
|
.SH "NAME"
|
|
crl \- \s-1CRL\s0 utility
|
|
.SH "LIBRARY"
|
|
libcrypto, -lcrypto
|
|
.SH "SYNOPSIS"
|
|
.IX Header "SYNOPSIS"
|
|
\&\fBopenssl\fR \fBcrl\fR
|
|
[\fB\-inform PEM|DER\fR]
|
|
[\fB\-outform PEM|DER\fR]
|
|
[\fB\-text\fR]
|
|
[\fB\-in filename\fR]
|
|
[\fB\-out filename\fR]
|
|
[\fB\-noout\fR]
|
|
[\fB\-hash\fR]
|
|
[\fB\-issuer\fR]
|
|
[\fB\-lastupdate\fR]
|
|
[\fB\-nextupdate\fR]
|
|
[\fB\-CAfile file\fR]
|
|
[\fB\-CApath dir\fR]
|
|
.SH "DESCRIPTION"
|
|
.IX Header "DESCRIPTION"
|
|
The \fBcrl\fR command processes \s-1CRL\s0 files in \s-1DER\s0 or \s-1PEM\s0 format.
|
|
.SH "COMMAND OPTIONS"
|
|
.IX Header "COMMAND OPTIONS"
|
|
.Ip "\fB\-inform DER|PEM\fR" 4
|
|
.IX Item "-inform DER|PEM"
|
|
This specifies the input format. \fB\s-1DER\s0\fR format is \s-1DER\s0 encoded \s-1CRL\s0
|
|
structure. \fB\s-1PEM\s0\fR (the default) is a base64 encoded version of
|
|
the \s-1DER\s0 form with header and footer lines.
|
|
.Ip "\fB\-outform DER|PEM\fR" 4
|
|
.IX Item "-outform DER|PEM"
|
|
This specifies the output format, the options have the same meaning as the
|
|
\&\fB\-inform\fR option.
|
|
.Ip "\fB\-in filename\fR" 4
|
|
.IX Item "-in filename"
|
|
This specifies the input filename to read from or standard input if this
|
|
option is not specified.
|
|
.Ip "\fB\-out filename\fR" 4
|
|
.IX Item "-out filename"
|
|
specifies the output filename to write to or standard output by
|
|
default.
|
|
.Ip "\fB\-text\fR" 4
|
|
.IX Item "-text"
|
|
print out the \s-1CRL\s0 in text form.
|
|
.Ip "\fB\-noout\fR" 4
|
|
.IX Item "-noout"
|
|
don't output the encoded version of the \s-1CRL\s0.
|
|
.Ip "\fB\-hash\fR" 4
|
|
.IX Item "-hash"
|
|
output a hash of the issuer name. This can be use to lookup CRLs in
|
|
a directory by issuer name.
|
|
.Ip "\fB\-issuer\fR" 4
|
|
.IX Item "-issuer"
|
|
output the issuer name.
|
|
.Ip "\fB\-lastupdate\fR" 4
|
|
.IX Item "-lastupdate"
|
|
output the lastUpdate field.
|
|
.Ip "\fB\-nextupdate\fR" 4
|
|
.IX Item "-nextupdate"
|
|
output the nextUpdate field.
|
|
.Ip "\fB\-CAfile file\fR" 4
|
|
.IX Item "-CAfile file"
|
|
verify the signature on a \s-1CRL\s0 by looking up the issuing certificate in
|
|
\&\fBfile\fR
|
|
.Ip "\fB\-CApath dir\fR" 4
|
|
.IX Item "-CApath dir"
|
|
verify the signature on a \s-1CRL\s0 by looking up the issuing certificate in
|
|
\&\fBdir\fR. This directory must be a standard certificate directory: that
|
|
is a hash of each subject name (using \fBx509 \-hash\fR) should be linked
|
|
to each certificate.
|
|
.SH "NOTES"
|
|
.IX Header "NOTES"
|
|
The \s-1PEM\s0 \s-1CRL\s0 format uses the header and footer lines:
|
|
.PP
|
|
.Vb 2
|
|
\& -----BEGIN X509 CRL-----
|
|
\& -----END X509 CRL-----
|
|
.Ve
|
|
.SH "EXAMPLES"
|
|
.IX Header "EXAMPLES"
|
|
Convert a \s-1CRL\s0 file from \s-1PEM\s0 to \s-1DER:\s0
|
|
.PP
|
|
.Vb 1
|
|
\& openssl crl -in crl.pem -outform DER -out crl.der
|
|
.Ve
|
|
Output the text form of a \s-1DER\s0 encoded certificate:
|
|
.PP
|
|
.Vb 1
|
|
\& openssl crl -in crl.der -text -noout
|
|
.Ve
|
|
.SH "BUGS"
|
|
.IX Header "BUGS"
|
|
Ideally it should be possible to create a \s-1CRL\s0 using appropriate options
|
|
and files too.
|
|
.SH "SEE ALSO"
|
|
.IX Header "SEE ALSO"
|
|
openssl_crl2pkcs7(1), openssl_ca(1), openssl_x509(1)
|