certtool(1) (User Commands) certtool(1) (NAME) certtool - GnuTLS (SYNOPSIS) certtool [-flags] [-flag [value]] [--option-name[[=| ]value]] . (DESCRIPTION) X.509. . URI --infile . URI (PIN) GNUTLS_PIN GNUTLS_SO_PIN . (OPTIONS) -d num, --debug=num (). . num : 0 9999 . -V, --verbose . --infile=file . --outfile=str . --attime=timestamp . "29 Feb 2004" "2004-02-29" . 'info '(coreutils) date invocation . (Certificate related options) -i, --certificate-info . --pubkey-info . --load-request --load-pubkey --load-privkey --load-certificate . -s, --generate-self-signed . -c, --generate-certificate . --generate-proxy . -u, --update-certificate . --fingerprint () . DER . --hash . key-id . --key-id (Key ID) . . . --certificate-pubkey . --pubkey-info . : --v1 X.509 ( ). --sign-params=str . --generate-certificate . 'RSA-PSS' RSA-PSS . (Certificate request related options) --crq-info . -q, --generate-request PKCS #10. : infile. PKCS #10 . --load-privkey . --no-crq-extensions . PKCS#12 (PKCS#12 file related options) --p12-info PKCS #12. PKCS #12 . --p12-name=str (friendly name) PKCS #12. PKCS #12 . --to-p12 PKCS #12. CA . --pbmac1 PBMAC1 PKCS #12. (Private key related options) -k, --key-info . --p8-info PKCS #8. PKCS #8 . . --to-rsa RSA-PSS RSA. RSA-PSS RSA . RSA-PSS . -p, --generate-privkey . RSA-PSS RSA-OAEP --hash RSA-PSS --salt-size . --key-type=str . --generate-privkey . 'rsa' 'rsa-pss' 'rsa-oaep' 'dsa' 'ecdsa' 'ed25519' 'ed448' 'x25519' 'x448'. RSA-PSS RSA . --key-format=str . --generate-privkey ML-DSA . 'seed' 'expanded' 'both' . --bits=num . . --curve=str EC. secp192r1 secp224r1 secp256r1 secp384r1 secp521r1. --sec-param=security parameter [low, legacy, medium, high, ultra]. bits . --to-p8 PKCS #8. --load-privkey . -8, --pkcs8 PKCS #8 . --provable (seed) . FIPS PUB186-4 ( Shawe-Taylor) . (seed) --verify-provable-privkey . --seed GnuTLS ( ). --generate-privkey --generate-dh-params . RSA DSA . DSA PQG RSA . --verify-provable-privkey . FIPS-186-4 . --seed . --seed=str . ( ). CRL (CRL related options) -l, --crl-info CRL . --generate-crl CRL. (CRL) . --load-crl CRL CRL ( CRL ). CRL --load-certificate . --verify-crl (CRL) . : load-ca-certificate. --load-ca-certificate . (Certificate verification related options) -e, --verify-chain PEM. . . . --verify-purpose --verify-hostname . --verify ( ) PEM . --load-ca-certificate . . . . --verify-purpose --verify-hostname . --verify-hostname=str . . --verify-email=str . : verify-hostname. . --verify-purpose=str OID . . 1.3.6.1.5.5.7.3.1 (TLS WWW) 1.3.6.1.5.5.7.3.4 (EMAIL) . CA ( ) . --verify-allow-broken MD5 . --p7-verify --verify --verify-chain . --verify-profile=str . . . 'none' 'very weak' 'low' 'legacy' 'medium' 'high' 'ultra' 'future' . gnutls . PKCS#7 (PKCS#7 structure options) --p7-generate PKCS #7. PKCS #7 . --load-certificate --load-crl . --p7-sign PKCS #7. PKCS #7 infile . . --load-certificate --load-privkey . --load-certificate . . --p7-detached-sign PKCS #7. PKCS #7 infile . --load-certificate --load-privkey . --load-certificate . . --p7-include-cert, --no-p7-include-cert . no-p7-include-cert . . --p7-sign --p7-detached-sign . --p7-time, --no-p7-time PKCS #7 . no-p7-time . . --p7-show-data, --no-p7-show-data PKCS #7 . no-p7-show-data . --p7-verify --p7-info PKCS #7 . --p7-info PKCS #7. --p7-verify PKCS #7 . PKCS #7 . --load-ca-certificate . . --load-certificate . --verify-purpose --load-data . --smime-to-p7 S/MIME PKCS #7. (Other options) --generate-dh-params - (Diffie-Hellman) PKCS #3. - . PKCS #3 . --get-dh-params . : --get-dh-params - PKCS #3. DH GnuTLS . RFC7919 TLS . DH GnuTLS . --dh-info - PKCS #3. --load-privkey=str . (URL) PKCS #11 . --load-pubkey=str . (URL) PKCS #11 . --load-request=str . . --load-certificate=str . . --load-ca-privkey=str (CA). (URL) PKCS #11 . --load-ca-certificate=str (CA). (URL) PKCS #11 . --load-crl=str CRL . . --load-data=str . . --password=str . tty . . '' . --null-password NULL. NULL . PKCS #8 . --empty-password (empty). . NULL PKCS #8 . --hex-numbers . --cprint C . C C . --rsa RSA. --generate-privkey RSA . : --dsa DSA. --generate-privkey DSA . : --ecc ECC (ECDSA). --generate-privkey ECDSA . : --ecdsa --ecc . : --hash=str () . SHA1 RMD160 SHA256 SHA384 SHA512 SHA3-224 SHA3-256 SHA3-384 SHA3-512. --salt-size=num (salt) RSA-PSS. . . --label=str RSA-OAEP . . --inder, --no-inder DER DH . no-inder . DER RAW . PEM ( ) DER . --inraw --inder . --outder, --no-outder DER DH . no-outder . DER RAW . --outraw --outder . --disable-quick-random . : --template=str . --stdout-info (stdout) (stderr). --ask-pass (batch). . template . --pkcs-cipher=cipher PKCS #8 #12. 3des 3des-pkcs12 aes-128 aes-192 aes-256 rc2-40 arcfour . --provider=str PKCS #11. /etc/gnutls/pkcs11.conf . --text, --no-text PEM. no-text . . PEM -v arg, --version=arg . 'v' . 'c' 'n' . -h, --help . -!, --more-help (pager). (FILES) Certtool certtool . 'cert.cfg' . : $ certtool --generate-certificate --load-privkey key.pem --template cert.cfg --outfile cert.pem --load-ca-certificate ca-cert.pem --load-ca-privkey ca-key.pem certtool . # X.509 Certificate options # # DN # ( ). organization = "Koko inc." # . unit = "sleeping dept." # / . # locality = # / . state = "Attiki" # ( ). country = GR # (CN) . cn = "Cindy Lauper" # . #uid = "clauper" # #dc = "name" #dc = "domain" # OID DN # OID . # X.520 X.520 # OID . #dn_oid = "2.5.4.12 Dr." #dn_oid = "2.5.4.65 jackal" # # . # pkcs9_email = "none@none.org" # (DN) # "dn" . : # C () street O () OU ( ) title CN ( ) # L (/) ST () placeOfBirth gender countryOfCitizenship # countryOfResidence serialNumber telephoneNumber surName initials # generationQualifier givenName pseudonym dnQualifier postalCode name # businessCategory DC UID jurisdictionOfIncorporationLocalityName # jurisdictionOfIncorporationStateOrProvinceName # jurisdictionOfIncorporationCountryName XmppAddr OID . #dn = "cn = Nikos,st = New Something,C=GR,surName=Mavrogiannopoulos,2.5.4.9=Arkadias" # # ( 1963) ( 0x07ab) . # . serial = 007 # . # -1 . expiration_days = 700 # . GNU # . : # https://www.gnu.org/software/tar/manual/html_node/Date-input-formats.html #activation_date = "2004-02-29 16:21:42" #expiration_date = "2025-02-29 16:24:41" # X.509 v3 # (dnsname) . #dns_name = "www.none.org" #dns_name = "www.morethanone.org" # othername OID #other_name = "1.3.6.1.5.2.2 302ca00d1b0b56414e5245494e2e4f5247a11b3019a006020400000002a10f300d1b047269636b1b0561646d696e" #other_name_utf8 = "1.2.4.5.6 A UTF8 string" #other_name_octet = "1.2.4.5.6 A string that will be encoded as ASN.1 octet string" # XmppAddr #xmpp_name = juliet@im.example.com # PKINIT #krb5_principal = user@REALM.COM #krb5_principal = HTTP/user@REALM.COM # URI (SAN) #uri = "https://www.example.com" # IP . #ip_address = "192.168.1.1" # email = "none@none.org" # TLS (rfc7633). # TLS . # Status Request (extid: 5) # OCSP (stapled). # TLS . # OCSP : #tls_feature = 5 # (challenge password) challenge_password = 123456 # #password = secret # URL CRL ( ) . # CA. #crl_dist_points = "https://www.getcrl.crl/getcrl" # CA #ca # ( ) #subject_unique_id = 00153224 # ( ) #issuer_unique_id = 00153225 #### (Key usage) # CA # # ( TLS DHE). digitalSignature # RFC5280 . signing_key # # ( TLS RSA). # . keyEncipherment # RFC5280 . encryption_key # . # keyCertSign RFC5280. #cert_signing_key # CRL . # cRLSign RFC5280. #crl_signing_key # keyAgreement RFC5280. . # . #key_agreement # dataEncipherment RFC5280. . # . #data_encipherment # nonRepudiation RFC5280. . # . #non_repudiation #### ( ) # . # CA . # TLS # id-kp-clientAuth (1.3.6.1.5.5.7.3.2) # . #tls_www_client # TLS # id-kp-serverAuth (1.3.6.1.5.5.7.3.1) # . #tls_www_server # . # id-kp-codeSigning (1.3.6.1.5.5.7.3.3) # . #code_signing_key # OCSP . # id-kp-OCSPSigning (1.3.6.1.5.5.7.3.9) . #ocsp_signing_key # . # id-kp-timeStamping (1.3.6.1.5.5.7.3.8) . #time_stamping_key # . # id-kp-emailProtection (1.3.6.1.5.5.7.3.4) . #email_protection_key # IPsec IKE (1.3.6.1.5.5.7.3.17). #ipsec_ike_key ## OID # # key_purpose_oid = 1.3.6.1.4.1.311.20.2.2 # # key_purpose_oid = 1.3.6.1.5.5.7.3.4 # ( CA ) # key_purpose_oid = 2.5.29.37.0 ### OID ### # OID # . GnuTLS 3.5.3 . #add_extension = "1.2.3.4 0x0AAB01ACFE" # (octet string) #add_extension = "1.2.3.4 octet_string(0x0AAB01ACFE)" # . #add_critical_extension = "5.6.7.8 0x1AAB01ACFE" # # . #honor_crq_extensions # . #honor_crq_ext = 2.5.29.17 #honor_crq_ext = 2.5.29.15 # . # . # ( ) #path_len = -1 #path_len = 2 # URI OCSP # ocsp_uri = https://my.ocsp.server/ocsp # URI CA # ca_issuers_uri = https://my.ca.issuer # (Certificate policies) #policy1 = 1.3.6.1.4.1.5484.1.10.99.1.0 #policy1_txt = "This is a long policy to summarize" #policy1_url = https://www.example.com/a-policy-to-read #policy2 = 1.3.6.1.4.1.5484.1.10.99.1.1 #policy2_txt = "This is a short policy" #policy2_url = https://www.example.com/another-policy-to-read # # anyPolicy . #inhibit_anypolicy_skip_certs 1 # (Name constraints) # DNS #nc_permit_dns = example.com #nc_exclude_dns = test.example.com # EMAIL #nc_permit_email = "nmav@ex.net" # example.com #nc_exclude_email = .example.com # example.com #nc_exclude_email = example.com # IP #nc_permit_ip = 192.168.0.0/16 #nc_exclude_ip = 192.168.5.0/24 #nc_permit_ip = fc0a:eef2:e7e7:a56e::/64 # #proxy_policy_language = 1.3.6.1.5.5.7.21.1 # CRL # CRL . # CRL 43 #crl_next_update = 43 # CRL CA # ( 1963) ( 0x07ab) . # . # CRL GnuTLS 3.6.3 # . # CRL # CRL 3.6.3 # CRL # CRL 2**63-2 . #crl_number = 5 # . #crl_this_update_date = "2004-02-29 16:21:42" #crl_next_update_date = "2025-02-29 16:24:41" # . #crl_revocation_date = "2025-02-29 16:24:41" (EXAMPLES) RSA : $ certtool --generate-privkey --outfile key.pem --rsa DSA (ECDSA) 'dsa' 'ecc' . ( ) : certtool --generate-request --load-privkey key.pem --outfile request.pem URL : $ ./certtool --generate-request --load-privkey "pkcs11:..." --load-pubkey "pkcs11:..." --outfile request.pem : $ certtool --generate-privkey --outfile ca-key.pem $ certtool --generate-self-signed --load-privkey ca-key.pem --outfile ca-cert.pem (CA) . : $ certtool --generate-certificate --load-request request.pem --outfile cert.pem --load-ca-certificate ca-cert.pem --load-ca-privkey ca-key.pem : $ certtool --generate-certificate --load-privkey key.pem --outfile cert.pem --load-ca-certificate ca-cert.pem --load-ca-privkey ca-key.pem : $ certtool --certificate-info --infile cert.pem PEM DER : $ certtool --certificate-info --infile cert.pem --outder --outfile cert.der PKCS #12 PKCS #12 : $ certtool --load-certificate cert.pem --load-privkey key.pem --to-p12 --outder --outfile key.p12 ( ) CA . --load-ca-certificate : $ certtool --load-ca-certificate ca.pem --load-certificate cert.pem --load-privkey key.pem --to-p12 --outder --outfile key.p12 - RFC7919 - : $ certtool --get-dh-params --outfile dh.pem --sec-param medium CA : $ certtool --verify --infile cert.pem : $ certtool --verify --verify-hostname www.example.com --infile cert.pem . : $ certtool --generate-privkey > proxy-key.pem $ certtool --generate-proxy --load-ca-privkey key.pem --load-privkey proxy-key.pem --load-certificate cert.pem --outfile proxy-cert.pem (CRL) (CRL) : $ certtool --generate-crl --load-ca-privkey x509-ca-key.pem --load-ca-certificate x509-ca.pem CRL --load-certificate : $ certtool --generate-crl --load-ca-privkey x509-ca-key.pem --load-ca-certificate x509-ca.pem --load-certificate revoked-certs.pem (CRL) : $ certtool --verify-crl --load-ca-certificate x509-ca.pem < crl.pem (EXIT STATUS) : 0 (EXIT_SUCCESS) . 1 (EXIT_FAILURE) . (SEE ALSO) p11tool(1) psktool(1) srptool(1) (AUTHORS) GnuTLS. (COPYRIGHT) (C) 2020-2023 Free Software Foundation . . (GNU General Public License) . (BUGS) bugs@gnutls.org . 3.8.13 29 Apr 2026 certtool(1)