123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136 |
- .\" Automatically generated by Pandoc 1.19.2.4
- .\"
- .TH "tpm2_certifyX509certutil" "1" "" "tpm2\-tools" "General Commands Manual"
- .hy
- .SH NAME
- .PP
- \f[B]tpm2_certifyX509certutil\f[](1) \- Generate partial X509
- certificate.
- .SH SYNOPSIS
- .PP
- \f[B]tpm2_certifyX509certutil\f[] [\f[I]OPTIONS\f[]]
- .SH DESCRIPTION
- .PP
- \f[B]tpm2_certifyX509certutil\f[](1) \- Generates a partial certificate
- that is suitable as the third input parameter for TPM2_certifyX509
- command.
- The certificate data is written into a file in DER format and can be
- examined using openssl asn1parse tool as follows:
- .IP
- .nf
- \f[C]
- openssl\ asn1parse\ \-in\ partial_cert.der\ \-inform\ DER
- \f[]
- .fi
- .SH OPTIONS
- .PP
- These are the available options:
- .IP \[bu] 2
- \f[B]\-o\f[], \f[B]\-\-outcert\f[]=\f[I]STRING\f[]: The output file
- where the certificate will be written to.
- The default is partial_cert.der Optional parameter.
- .IP \[bu] 2
- \f[B]\-d\f[], \f[B]\-\-days\f[]=\f[I]NUMBER\f[]: The number of days the
- certificate will be valid starting from today.
- The default is 3560 (10 years) Optional parameter.
- .IP \[bu] 2
- \f[B]\-i\f[], \f[B]\-\-issuer\f[]=\f[I]STRING\f[]: The ISSUER entry for
- the cert in the following format: \-\-issuer="C=US;O=org;OU=Org
- unit;CN=cname" Supported fields are:
- .RS 2
- .IP \[bu] 2
- C \- "Country", max size = 2
- .IP \[bu] 2
- O \- "Org", max size = 8
- .IP \[bu] 2
- OU \- "Org Unit", max size = 8
- .IP \[bu] 2
- CN \- "Common Name", max size = 8 The files need to be separated with
- semicolon.
- At list one supported field is required for the option to be valid.
- Optional parameter.
- .RE
- .IP \[bu] 2
- \f[B]\-s\f[], \f[B]\-\-subject\f[]=\f[I]STRING\f[]: The SUBJECT for the
- cert in the following format: \-\-subject="C=US;O=org;OU=Org
- unit;CN=cname" Supported fields are:
- .RS 2
- .IP \[bu] 2
- C \- "Country", max size = 2
- .IP \[bu] 2
- O \- "Org", max size = 8
- .IP \[bu] 2
- OU \- "Org Unit", max size = 8
- .IP \[bu] 2
- CN \- "Common Name", max size = 8 The files need to be separated with
- semicolon.
- At list one supported field is required for the option to be valid.
- Optional parameter.
- .RE
- .IP \[bu] 2
- \f[B]ARGUMENT\f[] No arguments required.
- .SS References
- .SH COMMON OPTIONS
- .PP
- This collection of options are common to many programs and provide
- information that many users may expect.
- .IP \[bu] 2
- \f[B]\-h\f[], \f[B]\-\-help=[man|no\-man]\f[]: Display the tools
- manpage.
- By default, it attempts to invoke the manpager for the tool, however, on
- failure will output a short tool summary.
- This is the same behavior if the "man" option argument is specified,
- however if explicit "man" is requested, the tool will provide errors
- from man on stderr.
- If the "no\-man" option if specified, or the manpager fails, the short
- options will be output to stdout.
- .RS 2
- .PP
- To successfully use the manpages feature requires the manpages to be
- installed or on \f[I]MANPATH\f[], See man(1) for more details.
- .RE
- .IP \[bu] 2
- \f[B]\-v\f[], \f[B]\-\-version\f[]: Display version information for this
- tool, supported tctis and exit.
- .IP \[bu] 2
- \f[B]\-V\f[], \f[B]\-\-verbose\f[]: Increase the information that the
- tool prints to the console during its execution.
- When using this option the file and line number are printed.
- .IP \[bu] 2
- \f[B]\-Q\f[], \f[B]\-\-quiet\f[]: Silence normal tool output to stdout.
- .IP \[bu] 2
- \f[B]\-Z\f[], \f[B]\-\-enable\-errata\f[]: Enable the application of
- errata fixups.
- Useful if an errata fixup needs to be applied to commands sent to the
- TPM.
- Defining the environment TPM2TOOLS_ENABLE_ERRATA is equivalent.
- information many users may expect.
- .SH EXAMPLES
- .IP
- .nf
- \f[C]
- tpm2\ certifyX509certutil\ \-o\ partial_cert.der\ \-d\ 356
- \f[]
- .fi
- .SH Returns
- .PP
- Tools can return any of the following codes:
- .IP \[bu] 2
- 0 \- Success.
- .IP \[bu] 2
- 1 \- General non\-specific error.
- .IP \[bu] 2
- 2 \- Options handling error.
- .IP \[bu] 2
- 3 \- Authentication error.
- .IP \[bu] 2
- 4 \- TCTI related error.
- .IP \[bu] 2
- 5 \- Non supported scheme.
- Applicable to tpm2_testparams.
- .SH BUGS
- .PP
- Github Issues (https://github.com/tpm2-software/tpm2-tools/issues)
- .SH HELP
- .PP
- See the Mailing List (https://lists.01.org/mailman/listinfo/tpm2)
|