MODUTIL(1) MODUTIL(1) (NAME) modutil - PKCS #11 NSS (SYNOPSIS) modutil [] [[]] (STATUS) . NSS[1] . (DESCRIPTION) modutil PKCS #11 ( secmod.db) NSS . modutil PKCS #11 secmod.db . modutil PKCS #11 FIPS 140-2 . . . (OPTIONS) modutil ( ) . . -add modulename PKCS #11 . -libfile -ciphers -mechanisms . -changepw tokenname . . -pwfile -newpwfile . (PIN) . -chkfips FIPS . true FIPS false FIPS . -create . -dbdir . modutil . -default modulename . -mechanisms . -delete modulename . NSS PKCS #11 . -disable modulename . -slot . NSS PKCS #11 . -enable modulename . -slot . -fips [true | false] FIPS 140-2 NSS (true) (false) . -force modutil . . -jar JAR-file PKCS #11 JAR . -installdir -tempdir . JAR NSS PKCS #11 JAR ( PKCS #11 ) . JAR modutil . -list [modulename] secmod.db . modulename . -rawadd (module spec) secmod.db . -rawlist . -undefault modulename . -mechanisms . MODULE . MODULESPEC (module spec) . -ciphers cipher-enable-list . cipher-enable-list (:) . . -dbdir directory . modutil : (cert8.db key3.db secmod.db) SQLite (cert9.db key4.db pkcs11.txt). dbm: SQLite . --dbprefix prefix my_ my_cert9.db. . -installdir root-installation-directory -jar . . -libfile library-file PKCS #11 . -mechanisms mechanism-list . mechanism-list (:) . . . . modutil : RSA DSA RC2 RC4 RC5 AES DES DH SHA1 SHA256 SHA512 SSL TLS MD5 MD2 RANDOM ( ) FRIENDLY ( ). -newpwfile new-password-file -changepw . -nocertdb . : o -create . o -jar JAR . o -changepw NSS . -pwfile old-password-file -changepw . -secmod secmodname ( secmod.db) . -slot slotname -enable -disable . -string CONFIG_STRING . -tempdir temporary-directory -jar . . (USAGE AND EXAMPLES) . modutil . . modutil -create -dbdir directory PKCS #11 . modutil JAR . : modutil -add modulename -libfile library-file [-ciphers cipher-enable-list] [-mechanisms mechanism-list] : modutil -dbdir /home/my/sharednssdb -add "Example PKCS #11 Module" -libfile "/tmp/crypto.so" -mechanisms RSA:DSA:RC2:RANDOM Using database directory ... Module "Example PKCS #11 Module" added to database. JAR PKCS #11 JAR . JAR << JAR>> . JAR . : Platforms { Linux:5.4.08:x86 { ModuleName { "Example PKCS #11 Module" } ModuleFile { crypto.so } DefaultMechanismFlags{0x0000} CipherEnableFlags{0x0000} Files { crypto.so { Path{ /tmp/crypto.so } } setup.sh { Executable Path{ /tmp/setup.sh } } } } Linux:6.0.0:x86 { EquivalentPlatform { Linux:5.4.08:x86 } } } JAR -jar . modutil -dbdir /home/mt"jar-install-filey/sharednssdb -jar install.jar -installdir /home/my/sharednssdb This installation JAR file was signed by: ---------------------------------------------- **SUBJECT NAME** C=US, ST=California, L=Mountain View, CN=Cryptorific Inc., OU=Digital ID Class 3 - Netscape Object Signing, OU="www.verisign.com/repository/CPS Incorp. by Ref.,LIAB.LTD(c)9 6", OU=www.verisign.com/CPS Incorp.by Ref . LIABILITY LTD.(c)97 VeriSign, OU=VeriSign Object Signing CA - Class 3 Organization, OU="VeriSign, Inc.", O=VeriSign Trust Network **ISSUER NAME**, OU=www.verisign.com/CPS Incorp.by Ref. LIABILITY LTD.(c)97 VeriSign, OU=VeriSign Object Signing CA - Class 3 Organization, OU="VeriSign, Inc.", O=VeriSign Trust Network ---------------------------------------------- Do you wish to continue this installation? (y/n) y Using installer script "installer_script" Successfully parsed installation script Current platform is Linux:5.4.08:x86 Using installation parameters for platform Linux:5.4.08:x86 Installed file crypto.so to /tmp/crypto.so Installed file setup.sh to ./pk11inst.dir/setup.sh Executing "./pk11inst.dir/setup.sh"... "./pk11inst.dir/setup.sh" executed successfully Installed module "Example PKCS #11 Module" into module database Installation completed successfully . -rawadd . -rawlist . modutil -rawadd modulespec PKCS #11 secmod.db : modutil -delete modulename -dbdir directory secmod.db PKCS #11 . . -list . modutil -list [modulename] -dbdir directory . : modutil -list -dbdir /home/my/sharednssdb Listing of PKCS #11 Modules ----------------------------------------------------------- 1. NSS Internal PKCS #11 Module slots: 2 slots attached status: loaded slot: NSS Internal Cryptographic Services token: NSS Generic Crypto Services uri: pkcs11:token=NSS%20Generic%20Crypto%20Services;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 slot: NSS User Private Key and Certificate Services token: NSS Certificate DB uri: pkcs11:token=NSS%20Certificate%20DB;manufacturer=Mozilla%20Foundation;serial=0000000000000000;model=NSS%203 ----------------------------------------------------------- -list . : modutil -list "NSS Internal PKCS #11 Module" -dbdir /home/my/sharednssdb ----------------------------------------------------------- Name: NSS Internal PKCS #11 Module Library file: **Internal ONLY module** Manufacturer: Mozilla Foundation Description: NSS Internal Crypto Services PKCS #11 Version 2.20 Library Version: 3.11 Cipher Enable Flags: None Default Mechanism Flags: RSA:RC2:RC4:DES:DH:SHA1:MD5:MD2:SSL:TLS:AES Slot: NSS Internal Cryptographic Services Slot Mechanism Flags: RSA:RC2:RC4:DES:DH:SHA1:MD5:MD2:SSL:TLS:AES Manufacturer: Mozilla Foundation Type: Software Version Number: 3.11 Firmware Version: 0.0 Status: Enabled Token Name: NSS Generic Crypto Services Token Manufacturer: Mozilla Foundation Token Model: NSS 3 Token Serial Number: 0000000000000000 Token Version: 4.0 Token Firmware Version: 0.0 Access: Write Protected Login Type: Public (no login required) User Pin: NOT Initialized Slot: NSS User Private Key and Certificate Services Slot Mechanism Flags: None Manufacturer: Mozilla Foundation Type: Software Version Number: 3.11 Firmware Version: 0.0 Status: Enabled Token Name: NSS Certificate DB Token Manufacturer: Mozilla Foundation Token Model: NSS 3 Token Serial Number: 0000000000000000 Token Version: 8.3 Token Firmware Version: 0.0 Access: NOT Write Protected Login Type: Login required User Pin: Initialized -rawlist . ( -rawadd .) modutil -rawlist -dbdir /home/my/sharednssdb name="NSS Internal PKCS #11 Module" parameters="configdir=. certPrefix= keyPrefix= secmod=secmod.db flags=readOnly " NSS="trustOrder=75 cipherOrder=100 slotParams={0x00000001=[slotFlags=RSA,RC4,RC2,DES,DH,SHA1,MD5,MD2,SSL,TLS,AES,RANDOM askpw=any timeout=30 ] } Flags=internal,critical" . ( ). modutil -default modulename -mechanisms mechanism-list -default . NSS . : modutil -default "NSS Internal PKCS #11 Module" -dbdir -mechanisms RSA:DSA:RC2 Using database directory c:\databases... Successfully changed defaults. : modutil -undefault "NSS Internal PKCS #11 Module" -dbdir -mechanisms MD2:MD5 modutil . : modutil -enable|-disable modulename [-slot slotname] : modutil -enable "NSS Internal PKCS #11 Module" -slot "NSS Internal Cryptographic Services " -dbdir . Slot "NSS Internal Cryptographic Services " enabled. . . FIPS NSS modutil -fips FIPS 140-2 . : modutil -fips true -dbdir /home/my/sharednssdb/ FIPS mode enabled. FIPS -chkfips true false ( ). FIPS . modutil -chkfips false -dbdir /home/my/sharednssdb/ FIPS mode enabled. : modutil -changepw tokenname [-pwfile old-password-file] [-newpwfile new-password-file] modutil -dbdir /home/my/sharednssdb -changepw "NSS Certificate DB" Enter old password: Incorrect password, try again... Enter old password: Enter new password: Re-enter new password: Token "Communicator Certificate DB" password changed successfully. JAR (JAR INSTALLATION FILE FORMAT) JAR modutil . : o JAR . o . o Pkcs11_install_script . signtool . PKCS #11 pk11install . signtool : + Pkcs11_install_script: pk11install . . ForwardCompatible { IRIX:6.2:mips SUNOS:5.5.1:sparc } Platforms { WINNT::x86 { ModuleName { "Example Module" } ModuleFile { win32/fort32.dll } DefaultMechanismFlags{0x0001} DefaultCipherFlags{0x0001} Files { win32/setup.exe { Executable RelativePath { %temp%/setup.exe } } win32/setup.hlp { RelativePath { %temp%/setup.hlp } } win32/setup.cab { RelativePath { %temp%/setup.cab } } } } SUNOS:5.5.1:sparc { ModuleName { "Example UNIX Module" } ModuleFile { unix/fort.so } DefaultMechanismFlags{0x0001} CipherEnableFlags{0x0001} Files { unix/fort.so { RelativePath{%root%/lib/fort.so} AbsolutePath{/usr/local/netscape/lib/fort.so} FilePermissions{555} } xplat/instr.html { RelativePath{%root%/docs/inst.html} AbsolutePath{/usr/local/netscape/docs/inst.html} FilePermissions{555} } } } IRIX:6.2:mips { EquivalentPlatform { SUNOS:5.5.1:sparc } } } - . --> valuelist valuelist --> value valuelist value ---> key_value_pair string key_value_pair --> key { valuelist } key --> string string --> simple_string "complex_string" simple_string --> [^ \t\n\""{""}"]+ complex_string --> ([^\"\\\r\n]|(\\\")|(\\\\))+ . . ( ) . . ForwardCompatible . ForwardCompatible . . Platforms () . - : . system name:OS release:architecture . NSPR . OS release . NSPR : o AIX (rs6000) o BSDI (x86) o FREEBSD (x86) o HPUX (hppa1.1) o IRIX (mips) o LINUX (ppc, alpha, x86) o MacOS (PowerPC) o NCR (x86) o NEC (mips) o OS2 (x86) o OSF (alpha) o ReliantUNIX (mips) o SCO (x86) o SOLARIS (sparc) o SONY (mips) o SUNOS (sparc) o UnixWare (x86) o WIN16 (x86) o WIN95 (x86) o WINNT (x86) : IRIX:6.2:mips SUNOS:5.5.1:sparc Linux:2.0.32:x86 WIN95::x86 ModuleName ModuleFile Files . EquivalentPlatform . Platforms . ModuleName () . modutil . ModuleFile () PKCS #11 . JAR . Files () . - . JAR . RelativePath AbsolutePath . DefaultMechanismFlags -mechanism -add . - (0x) OR . DefaultMechanismFlags 0x0 . RSA: 0x00000001 DSA: 0x00000002 RC2: 0x00000004 RC4: 0x00000008 DES: 0x00000010 DH: 0x00000020 FORTEZZA: 0x00000040 RC5: 0x00000080 SHA1: 0x00000100 MD5: 0x00000200 MD2: 0x00000400 RANDOM: 0x08000000 FRIENDLY: 0x10000000 OWN_PW_DEFAULTS: 0x20000000 DISABLE: 0x40000000 CipherEnableFlags NSS ( NSS ). -cipher -add . (0x) OR . CipherEnableFlags 0x0 . EquivalentPlatform . . Files . . RelativePath AbsolutePath . . RelativePath . : %root% %temp%. %root% . %temp% . %temp% ( ) . . AbsolutePath . Executable . ( -) . . FilePermissions ( ) . OR . user read: 0400 user write: 0200 user execute: 0100 group read: 0040 group write: 0020 group execute: 0010 other read: 0004 other write: 0002 other execute: 0001 . . 777 . NSS (NSS DATABASE TYPES) NSS BerkeleyDB . (legacy) : o cert8.db o key3.db o secmod.db PKCS #11 BerkeleyDB . NSS . NSS . NSS BerkeleyDB SQLite . : o cert9.db o key4.db o pkcs11.txt PKCS #11 SQLite (shared) . . (certutil pk12util modutil) SQLite . dbm: . : modutil -create -dbdir dbm:/home/my/sharednssdb NSS_DEFAULT_DB_TYPE dbm : export NSS_DEFAULT_DB_TYPE="dbm" ~/.bashrc . o https://wiki.mozilla.org/NSS_Shared_DB_Howto NSS NSS : o https://wiki.mozilla.org/NSS_Shared_DB (SEE ALSO) certutil (1) pk12util (1) signtool (1) NSS . o https://wiki.mozilla.org/NSS_Shared_DB_Howto o https://wiki.mozilla.org/NSS_Shared_DB (ADDITIONAL RESOURCES) NSS NSS ( JSS) NSS http://www.mozilla.org/projects/security/pki/nss . NSS NSS . : https://lists.mozilla.org/listinfo/dev-tech-crypto (IRC): Freenode #dogtag-pki (AUTHORS) NSS Netscape Red Hat Sun Oracle Mozilla Google . : Elio Maldonado Deon Lackey . (LICENSE) (MPL) . . MPL http://mozilla.org/MPL/2.0 . (NOTES) 1. Mozilla NSS bug 836477 https://bugzilla.mozilla.org/show_bug.cgi?id=836477 nss MODUTIL(1)