OpenSSL CRL2PKCS7(1openssl) NNNNAAAAMMMMEEEE
crl2pkcs7 - Create a PKCS#7 structure from a CRL and
certificates. SSSSYYYYNNNNOOOOPPPPSSSSIIIISSSSooooppppeeeennnnssssssssllll ccccrrrrllll2222ppppkkkkccccssss7777 [---iiinnnnffffoooorrrrmmmm PPPPEEEEMMMM||||DDDDEEEERRRR] [---ooouuuuttttffffoooorrrrmmmm PPPPEEEEMMMM||||DDDDEEEERRRR] [---iiinnnn
ffffiiiilllleeeennnnaaaammmmeeee] [---ooouuuutttt ffffiiiilllleeeennnnaaaammmmeeee] [---ccceeeerrrrttttffffiiiilllleeee ffffiiiilllleeeennnnaaaammmmeeee] [---nnnooooccccrrrrllll]
DDDDEEEESSSSCCCCRRRRIIIIPPPPTTTTIIIIOOOONNNN The ccccrrrrllll2222ppppkkkkccccssss7777 command takes an optional CRL and one or morecertificates and converts them into a PKCS#7 degenerate
"certificates only" structure. CCCCOOOOMMMMMMMMAAAANNNNDDDD OOOOPPPPTTTTIIIIOOOONNNNSSSS-iiiinnnnffffoooorrrrmmmm DDDDEEEERRRR||||PPPPEEEEMMMM
This specifies the CRL input format. DDDDEEEERRRR format is DER encoded CRL structure.PPPPEEEEMMMM (the default) is a base64 encoded version of the DER form with header and footer lines.-oooouuuuttttffffoooorrrrmmmm DDDDEEEERRRR||||PPPPEEEEMMMM
This specifies the PKCS#7 structure output format. DDDDEEEERRRR
format is DER encoded PKCS#7 structure.PPPPEEEEMMMM (the default)
is a base64 encoded version of the DER form with header and footer lines.-iiiinnnn ffffiiiilllleeeennnnaaaammmmeeee
This specifies the input filename to read a CRL from or standard input if this option is not specified.-oooouuuutttt ffffiiiilllleeeennnnaaaammmmeeee
specifies the output filename to write the PKCS#7
structure to or standard output by default.-cccceeeerrrrttttffffiiiilllleeee ffffiiiilllleeeennnnaaaammmmeeee
specifies a filename containing one or more certificates in PPPPEEEEMMMM format. All certificates in the file will beadded to the PKCS#7 structure. This option can be used
more than once to read certificates form multiple files.-nnnnooooccccrrrrllll
normally a CRL is included in the output file. With this option no CRL is included in the output file and a CRL is not read from the input file. EEEEXXXXAAAAMMMMPPPPLLLLEEEESSSSCreate a PKCS#7 structure from a certificate and CRL:
openssl crl2pkcs7 -in crl.pem -certfile cert.pem -out p7.pem
Creates a PKCS#7 structure in DER format with no CRL from
several different certificates:9/Jul/2002 Last change: 0.9.8o 1 OpenSSL CRL2PKCS7(1openssl)
openssl crl2pkcs7 -nocrl -certfile newcert.pem
-certfile demoCA/cacert.pem -outform DER -out p7.der
NNNNOOOOTTTTEEEESSSSThe output file is a PKCS#7 signed data structure containing
no signers and just certificates and an optional CRL. This utility can be used to send certificates and CAs to Netscape as part of the certificate enrollment process. This involves sending the DER encoded output as MIME typeapplication/x-x509-user-cert.
The PPPPEEEEMMMM encoded form with the header and footer lines removed can be used to install user certificates and CAs in MSIE using the Xenroll control. SSSSEEEEEEEE AAAALLLLSSSSOOOO pkcs7(1)9/Jul/2002 Last change: 0.9.8o 2