CRL(1) OpenSSL CRL(1) NNAAMMEE openssl-crl, crl - CRL utility SSYYNNOOPPSSIISS ooppeennssssll ccrrll [--iinnffoorrmm PPEEMM||DDEERR] [--oouuttffoorrmm PPEEMM||DDEERR] [--tteexxtt] [--iinn ffiilleennaammee] [--oouutt ffiilleennaammee] [--nnaammeeoopptt ooppttiioonn] [--nnoooouutt] [--hhaasshh] [--iissssuueerr] [--llaassttuupp-- ddaattee] [--nneexxttuuppddaattee] [--CCAAffiillee ffiillee] [--CCAAppaatthh ddiirr] DDEESSCCRRIIPPTTIIOONN The ccrrll command processes CRL files in DER or PEM format. CCOOMMMMAANNDD OOPPTTIIOONNSS --iinnffoorrmm DDEERR||PPEEMM This specifies the input format. DDEERR format is DER encoded CRL structure. PPEEMM (the default) is a base64 encoded version of the DER form with header and footer lines. --oouuttffoorrmm DDEERR||PPEEMM This specifies the output format, the options have the same meaning as the --iinnffoorrmm option. --iinn ffiilleennaammee This specifies the input filename to read from or standard input if this option is not specified. --oouutt ffiilleennaammee specifies the output filename to write to or standard output by default. --tteexxtt print out the CRL in text form. --nnaammeeoopptt ooppttiioonn option which determines how the subject or issuer names are dis- played. See the description of --nnaammeeoopptt in _x_5_0_9(1). --nnoooouutt don't output the encoded version of the CRL. --hhaasshh output a hash of the issuer name. This can be use to lookup CRLs in a directory by issuer name. --hhaasshh__oolldd outputs the "hash" of the CRL issuer name using the older algorithm as used by OpenSSL versions before 1.0.0. --iissssuueerr output the issuer name. --llaassttuuppddaattee output the lastUpdate field. --nneexxttuuppddaattee output the nextUpdate field. --CCAAffiillee ffiillee verify the signature on a CRL by looking up the issuing certificate in ffiillee --CCAAppaatthh ddiirr verify the signature on a CRL by looking up the issuing certificate in ddiirr. This directory must be a standard certificate directory: that is a hash of each subject name (using xx550099 --hhaasshh) should be linked to each certificate. NNOOTTEESS The PEM CRL format uses the header and footer lines: -----BEGIN X509 CRL----- -----END X509 CRL----- EEXXAAMMPPLLEESS Convert a CRL file from PEM to DER: openssl crl -in crl.pem -outform DER -out crl.der Output the text form of a DER encoded certificate: openssl crl -in crl.der -inform DER -text -noout BBUUGGSS Ideally it should be possible to create a CRL using appropriate options and files too. SSEEEE AALLSSOO _c_r_l_2_p_k_c_s_7(1), _c_a(1), _x_5_0_9(1) 1.0.2u 2019-12-20 CRL(1)