OpenSSL CRL(1openssl) NNNNAAAAMMMMEEEE
crl - CRL utility
SSSSYYYYNNNNOOOOPPPPSSSSIIIISSSSooooppppeeeennnnssssssssllll ccccrrrrllll [---iiinnnnffffoooorrrrmmmm PPPPEEEEMMMM||||DDDDEEEERRRR] [---ooouuuuttttffffoooorrrrmmmm PPPPEEEEMMMM||||DDDDEEEERRRR] [---ttteeeexxxxtttt]
[---iiinnnn ffffiiiilllleeeennnnaaaammmmeeee] [---ooouuuutttt ffffiiiilllleeeennnnaaaammmmeeee] [---nnnoooooooouuuutttt] [---hhhaaaasssshhhh] [---iiissssssssuuuueeeerrrr]
[---lllaaaassssttttuuuuppppddddaaaatttteeee] [---nnneeeexxxxttttuuuuppppddddaaaatttteeee] [---CCCAAAAffffiiiilllleeee ffffiiiilllleeee] [---CCCAAAAppppaaaatttthhhh ddddiiiirrrr]
DDDDEEEESSSSCCCCRRRRIIIIPPPPTTTTIIIIOOOONNNN The ccccrrrrllll command processes CRL files in DER or PEM format. CCCCOOOOMMMMMMMMAAAANNNNDDDD OOOOPPPPTTTTIIIIOOOONNNNSSSS-iiiinnnnffffoooorrrrmmmm DDDDEEEERRRR||||PPPPEEEEMMMM
This specifies the input format. DDDDEEEERRRR format is DER encoded CRL structure. PPPPEEEEMMMM (the default) is a base64 encoded version of the DER form with header and footer lines.-oooouuuuttttffffoooorrrrmmmm DDDDEEEERRRR||||PPPPEEEEMMMM
This specifies the output format, the options have thesame meaning as the ---iiinnnnffffoooorrrrmmmm option.
-iiiinnnn ffffiiiilllleeeennnnaaaammmmeeee
This specifies the input filename to read from or standard input if this option is not specified.-oooouuuutttt ffffiiiilllleeeennnnaaaammmmeeee
specifies the output filename to write to or standard output by default.-tttteeeexxxxtttt
print out the CRL in text form.-nnnnoooooooouuuutttt
don't output the encoded version of the CRL.-hhhhaaaasssshhhh
output a hash of the issuer name. This can be use to lookup CRLs in a directory by issuer name.-iiiissssssssuuuueeeerrrr
output the issuer name.-llllaaaassssttttuuuuppppddddaaaatttteeee
output the lastUpdate field.-nnnneeeexxxxttttuuuuppppddddaaaatttteeee
output the nextUpdate field.-CCCCAAAAffffiiiilllleeee ffffiiiilllleeee
verify the signature on a CRL by looking up the issuing certificate in ffffiiiilllleeee8/Feb/2000 Last change: 0.9.8o 1 OpenSSL CRL(1openssl)
-CCCCAAAAppppaaaatttthhhh ddddiiiirrrr
verify the signature on a CRL by looking up the issuing certificate in ddddiiiirrrr. This directory must be a standard certificate directory: that is a hash of each subjectname (using xxxx555500009999 ---hhhaaaasssshhhh) should be linked to each
certificate. NNNNOOOOTTTTEEEESSSS The PEM CRL format uses the header and footer lines:-----BEGIN X509 CRL-----
-----END X509 CRL-----
EEEEXXXXAAAAMMMMPPPPLLLLEEEESSSS Convert a CRL file from PEM to DER:openssl crl -in crl.pem -outform DER -out crl.der
Output the text form of a DER encoded certificate:openssl crl -in crl.der -text -noout
BBBBUUUUGGGGSSSS Ideally it should be possible to create a CRL using appropriate options and files too. SSSSEEEEEEEE AAAALLLLSSSSOOOOcrl2pkcs7(1), ca(1), x509(1)
8/Feb/2000 Last change: 0.9.8o 2 OpenSSL CRL(1openssl)
8/Feb/2000 Last change: 0.9.8o 3