openssl-format-options.1ossl 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265
  1. .\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42)
  2. .\"
  3. .\" Standard preamble:
  4. .\" ========================================================================
  5. .de Sp \" Vertical space (when we can't use .PP)
  6. .if t .sp .5v
  7. .if n .sp
  8. ..
  9. .de Vb \" Begin verbatim text
  10. .ft CW
  11. .nf
  12. .ne \\$1
  13. ..
  14. .de Ve \" End verbatim text
  15. .ft R
  16. .fi
  17. ..
  18. .\" Set up some character translations and predefined strings. \*(-- will
  19. .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
  20. .\" double quote, and \*(R" will give a right double quote. \*(C+ will
  21. .\" give a nicer C++. Capital omega is used to do unbreakable dashes and
  22. .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
  23. .\" nothing in troff, for use with C<>.
  24. .tr \(*W-
  25. .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
  26. .ie n \{\
  27. . ds -- \(*W-
  28. . ds PI pi
  29. . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
  30. . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
  31. . ds L" ""
  32. . ds R" ""
  33. . ds C` ""
  34. . ds C' ""
  35. 'br\}
  36. .el\{\
  37. . ds -- \|\(em\|
  38. . ds PI \(*p
  39. . ds L" ``
  40. . ds R" ''
  41. . ds C`
  42. . ds C'
  43. 'br\}
  44. .\"
  45. .\" Escape single quotes in literal strings from groff's Unicode transform.
  46. .ie \n(.g .ds Aq \(aq
  47. .el .ds Aq '
  48. .\"
  49. .\" If the F register is >0, we'll generate index entries on stderr for
  50. .\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
  51. .\" entries marked with X<> in POD. Of course, you'll have to process the
  52. .\" output yourself in some meaningful fashion.
  53. .\"
  54. .\" Avoid warning from groff about undefined register 'F'.
  55. .de IX
  56. ..
  57. .nr rF 0
  58. .if \n(.g .if rF .nr rF 1
  59. .if (\n(rF:(\n(.g==0)) \{\
  60. . if \nF \{\
  61. . de IX
  62. . tm Index:\\$1\t\\n%\t"\\$2"
  63. ..
  64. . if !\nF==2 \{\
  65. . nr % 0
  66. . nr F 2
  67. . \}
  68. . \}
  69. .\}
  70. .rr rF
  71. .\"
  72. .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
  73. .\" Fear. Run. Save yourself. No user-serviceable parts.
  74. . \" fudge factors for nroff and troff
  75. .if n \{\
  76. . ds #H 0
  77. . ds #V .8m
  78. . ds #F .3m
  79. . ds #[ \f1
  80. . ds #] \fP
  81. .\}
  82. .if t \{\
  83. . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
  84. . ds #V .6m
  85. . ds #F 0
  86. . ds #[ \&
  87. . ds #] \&
  88. .\}
  89. . \" simple accents for nroff and troff
  90. .if n \{\
  91. . ds ' \&
  92. . ds ` \&
  93. . ds ^ \&
  94. . ds , \&
  95. . ds ~ ~
  96. . ds /
  97. .\}
  98. .if t \{\
  99. . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
  100. . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
  101. . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
  102. . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
  103. . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
  104. . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
  105. .\}
  106. . \" troff and (daisy-wheel) nroff accents
  107. .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
  108. .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
  109. .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
  110. .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
  111. .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
  112. .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
  113. .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
  114. .ds ae a\h'-(\w'a'u*4/10)'e
  115. .ds Ae A\h'-(\w'A'u*4/10)'E
  116. . \" corrections for vroff
  117. .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
  118. .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
  119. . \" for low resolution devices (crt and lpr)
  120. .if \n(.H>23 .if \n(.V>19 \
  121. \{\
  122. . ds : e
  123. . ds 8 ss
  124. . ds o a
  125. . ds d- d\h'-1'\(ga
  126. . ds D- D\h'-1'\(hy
  127. . ds th \o'bp'
  128. . ds Th \o'LP'
  129. . ds ae ae
  130. . ds Ae AE
  131. .\}
  132. .rm #[ #] #H #V #F C
  133. .\" ========================================================================
  134. .\"
  135. .IX Title "OPENSSL-FORMAT-OPTIONS 1ossl"
  136. .TH OPENSSL-FORMAT-OPTIONS 1ossl "2024-09-03" "3.3.2" "OpenSSL"
  137. .\" For nroff, turn off justification. Always turn off hyphenation; it makes
  138. .\" way too many mistakes in technical documents.
  139. .if n .ad l
  140. .nh
  141. .SH "NAME"
  142. openssl\-format\-options \- OpenSSL command input and output format options
  143. .SH "SYNOPSIS"
  144. .IX Header "SYNOPSIS"
  145. \&\fBopenssl\fR
  146. \&\fIcommand\fR
  147. [ \fIoptions\fR ... ]
  148. [ \fIparameters\fR ... ]
  149. .SH "DESCRIPTION"
  150. .IX Header "DESCRIPTION"
  151. Several OpenSSL commands can take input or generate output in a variety
  152. of formats.
  153. .PP
  154. Since OpenSSL 3.0 keys, single certificates, and CRLs can be read from
  155. files in any of the \fB\s-1DER\s0\fR, \fB\s-1PEM\s0\fR or \fBP12\fR formats. Specifying their input
  156. format is no more needed and the openssl commands will automatically try all
  157. the possible formats. However if the \fB\s-1DER\s0\fR or \fB\s-1PEM\s0\fR input format is specified
  158. it will be enforced.
  159. .PP
  160. In order to access a key via an engine the input format \fB\s-1ENGINE\s0\fR may be used;
  161. alternatively the key identifier in the <uri> argument of the respective key
  162. option may be preceded by \f(CW\*(C`org.openssl.engine:\*(C'\fR.
  163. See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1) for an example usage of the latter.
  164. .SH "OPTIONS"
  165. .IX Header "OPTIONS"
  166. .SS "Format Options"
  167. .IX Subsection "Format Options"
  168. The options to specify the format are as follows.
  169. Refer to the individual man page to see which options are accepted.
  170. .IP "\fB\-inform\fR \fIformat\fR, \fB\-outform\fR \fIformat\fR" 4
  171. .IX Item "-inform format, -outform format"
  172. The format of the input or output streams.
  173. .IP "\fB\-keyform\fR \fIformat\fR" 4
  174. .IX Item "-keyform format"
  175. Format of a private key input source.
  176. .IP "\fB\-CRLform\fR \fIformat\fR" 4
  177. .IX Item "-CRLform format"
  178. Format of a \s-1CRL\s0 input source.
  179. .SS "Format Option Arguments"
  180. .IX Subsection "Format Option Arguments"
  181. The possible format arguments are described below.
  182. Both uppercase and lowercase are accepted.
  183. .PP
  184. The list of acceptable format arguments, and the default,
  185. is described in each command documentation.
  186. .IP "\fB\s-1DER\s0\fR" 4
  187. .IX Item "DER"
  188. A binary format, encoded or parsed according to Distinguished Encoding Rules
  189. (\s-1DER\s0) of the \s-1ASN.1\s0 data language.
  190. .IP "\fB\s-1ENGINE\s0\fR" 4
  191. .IX Item "ENGINE"
  192. Used to specify that the cryptographic material is in an OpenSSL \fBengine\fR.
  193. An engine must be configured or specified using the \fB\-engine\fR option.
  194. A password or \s-1PIN\s0 may be supplied to the engine using the \fB\-passin\fR option.
  195. .IP "\fBP12\fR" 4
  196. .IX Item "P12"
  197. A DER-encoded file containing a PKCS#12 object.
  198. It might be necessary to provide a decryption password to retrieve
  199. the private key.
  200. .IP "\fB\s-1PEM\s0\fR" 4
  201. .IX Item "PEM"
  202. A text format defined in \s-1IETF RFC 1421\s0 and \s-1IETF RFC 7468.\s0 Briefly, this is
  203. a block of base\-64 encoding (defined in \s-1IETF RFC 4648\s0), with specific
  204. lines used to mark the start and end:
  205. .Sp
  206. .Vb 7
  207. \& Text before the BEGIN line is ignored.
  208. \& \-\-\-\-\- BEGIN object\-type \-\-\-\-\-
  209. \& OT43gQKBgQC/2OHZoko6iRlNOAQ/tMVFNq7fL81GivoQ9F1U0Qr+DH3ZfaH8eIkX
  210. \& xT0ToMPJUzWAn8pZv0snA0um6SIgvkCuxO84OkANCVbttzXImIsL7pFzfcwV/ERK
  211. \& UM6j0ZuSMFOCr/lGPAoOQU0fskidGEHi1/kW+suSr28TqsyYZpwBDQ==
  212. \& \-\-\-\-\- END object\-type \-\-\-\-\-
  213. \& Text after the END line is also ignored
  214. .Ve
  215. .Sp
  216. The \fIobject-type\fR must match the type of object that is expected.
  217. For example a \f(CW\*(C`BEGIN X509 CERTIFICATE\*(C'\fR will not match if the command
  218. is trying to read a private key. The types supported include:
  219. .Sp
  220. .Vb 10
  221. \& ANY PRIVATE KEY
  222. \& CERTIFICATE
  223. \& CERTIFICATE REQUEST
  224. \& CMS
  225. \& DH PARAMETERS
  226. \& DSA PARAMETERS
  227. \& DSA PUBLIC KEY
  228. \& EC PARAMETERS
  229. \& EC PRIVATE KEY
  230. \& ECDSA PUBLIC KEY
  231. \& ENCRYPTED PRIVATE KEY
  232. \& PARAMETERS
  233. \& PKCS #7 SIGNED DATA
  234. \& PKCS7
  235. \& PRIVATE KEY
  236. \& PUBLIC KEY
  237. \& RSA PRIVATE KEY
  238. \& SSL SESSION PARAMETERS
  239. \& TRUSTED CERTIFICATE
  240. \& X509 CRL
  241. \& X9.42 DH PARAMETERS
  242. .Ve
  243. .Sp
  244. The following legacy \fIobject-type\fR's are also supported for compatibility
  245. with earlier releases:
  246. .Sp
  247. .Vb 4
  248. \& DSA PRIVATE KEY
  249. \& NEW CERTIFICATE REQUEST
  250. \& RSA PUBLIC KEY
  251. \& X509 CERTIFICATE
  252. .Ve
  253. .IP "\fB\s-1SMIME\s0\fR" 4
  254. .IX Item "SMIME"
  255. An S/MIME object as described in \s-1IETF RFC 8551.\s0
  256. Earlier versions were known as \s-1CMS\s0 and are compatible.
  257. Note that the parsing is simple and might fail to parse some legal data.
  258. .SH "COPYRIGHT"
  259. .IX Header "COPYRIGHT"
  260. Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved.
  261. .PP
  262. Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use
  263. this file except in compliance with the License. You can obtain a copy
  264. in the file \s-1LICENSE\s0 in the source distribution or at
  265. <https://www.openssl.org/source/license.html>.