/opt/alt/openssl11/share/man/man1
NameSizeModeActions
asn1parse.1ssl112100644editdlrm
ca.1ssl334800644editdlrm
CA.pl.1ssl123690644editdlrm
ciphers.1ssl382080644editdlrm
cms.1ssl327160644editdlrm
crl.1ssl76790644editdlrm
crl2pkcs7.1ssl74400644editdlrm
c_rehash.1ssl87750644editdlrm
dgst.1ssl119010644editdlrm
dhparam.1ssl93180644editdlrm
dsa.1ssl100140644editdlrm
dsaparam.1ssl80020644editdlrm
ec.1ssl108930644editdlrm
ecparam.1ssl101970644editdlrm
enc.1ssl199230644editdlrm
engine.1ssl73500644editdlrm
errstr.1ssl50820644editdlrm
gendsa.1ssl71240644editdlrm
genpkey.1ssl160640644editdlrm
genrsa.1ssl82520644editdlrm
list.1ssl64980644editdlrm
nseq.1ssl63950644editdlrm
ocsp.1ssl241520644editdlrm
openssl-asn1parse.1ssl112100644editdlrm
openssl-ca.1ssl334800644editdlrm
openssl-ciphers.1ssl382080644editdlrm
openssl-cms.1ssl327160644editdlrm
openssl-crl.1ssl76790644editdlrm
openssl-crl2pkcs7.1ssl74400644editdlrm
openssl-c_rehash.1ssl87750644editdlrm
openssl-dgst.1ssl119010644editdlrm
openssl-dhparam.1ssl93180644editdlrm
openssl-dsa.1ssl100140644editdlrm
openssl-dsaparam.1ssl80020644editdlrm
openssl-ec.1ssl108930644editdlrm
openssl-ecparam.1ssl101970644editdlrm
openssl-enc.1ssl199230644editdlrm
openssl-engine.1ssl73500644editdlrm
openssl-errstr.1ssl50820644editdlrm
openssl-gendsa.1ssl71240644editdlrm
openssl-genpkey.1ssl160640644editdlrm
openssl-genrsa.1ssl82520644editdlrm
openssl-list.1ssl64980644editdlrm
openssl-nseq.1ssl63950644editdlrm
openssl-ocsp.1ssl241520644editdlrm
openssl-passwd.1ssl73480644editdlrm
openssl-pkcs7.1ssl72740644editdlrm
openssl-pkcs8.1ssl160300644editdlrm
openssl-pkcs12.1ssl183300644editdlrm
openssl-pkey.1ssl90220644editdlrm
openssl-pkeyparam.1ssl63230644editdlrm
openssl-pkeyutl.1ssl162520644editdlrm
openssl-prime.1ssl55090644editdlrm
openssl-rand.1ssl68380644editdlrm
openssl-rehash.1ssl87750644editdlrm
openssl-req.1ssl304900644editdlrm
openssl-rsa.1ssl106680644editdlrm
openssl-rsautl.1ssl109550644editdlrm
openssl-sess_id.1ssl90640644editdlrm
openssl-smime.1ssl236120644editdlrm
openssl-speed.1ssl71890644editdlrm
openssl-spkac.1ssl87330644editdlrm
openssl-srp.1ssl59330644editdlrm
openssl-storeutl.1ssl76600644editdlrm
openssl-s_client.1ssl371520644editdlrm
openssl-s_server.1ssl351190644editdlrm
openssl-s_time.1ssl123870644editdlrm
openssl-ts.1ssl286980644editdlrm
openssl-tsget.1ssl114300644editdlrm
openssl-verify.1ssl340230644editdlrm
openssl-version.1ssl54810644editdlrm
openssl-x509.1ssl384960644editdlrm
openssl.1ssl215960644editdlrm
passwd.1ssl73480644editdlrm
pkcs7.1ssl72740644editdlrm
pkcs8.1ssl160300644editdlrm
pkcs12.1ssl183300644editdlrm
pkey.1ssl90220644editdlrm
pkeyparam.1ssl63230644editdlrm
pkeyutl.1ssl162520644editdlrm
prime.1ssl55090644editdlrm
rand.1ssl68380644editdlrm
rehash.1ssl87750644editdlrm
req.1ssl304900644editdlrm
rsa.1ssl106680644editdlrm
rsautl.1ssl109550644editdlrm
sess_id.1ssl90640644editdlrm
smime.1ssl236120644editdlrm
speed.1ssl71890644editdlrm
spkac.1ssl87330644editdlrm
srp.1ssl59330644editdlrm
storeutl.1ssl76600644editdlrm
s_client.1ssl371520644editdlrm
s_server.1ssl351190644editdlrm
s_time.1ssl123870644editdlrm
ts.1ssl286980644editdlrm
tsget.1ssl114300644editdlrm
verify.1ssl340230644editdlrm
version.1ssl54810644editdlrm
x509.1ssl384960644editdlrm
Edit: /opt/alt/openssl11/share/man/man1/spkac.1ssl (8733B)
.\" Automatically generated by Pod::Man 4.11 (Pod::Simple 3.35) .\" .\" Standard preamble: .\" ======================================================================== .de Sp \" Vertical space (when we can't use .PP) .if t .sp .5v .if n .sp .. .de Vb \" Begin verbatim text .ft CW .nf .ne \\$1 .. .de Ve \" End verbatim text .ft R .fi .. .\" Set up some character translations and predefined strings. \*(-- will .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left .\" double quote, and \*(R" will give a right double quote. \*(C+ will .\" give a nicer C++. Capital omega is used to do unbreakable dashes and .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, .\" nothing in troff, for use with C<>. .tr \(*W- .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' .ie n \{\ . ds -- \(*W- . ds PI pi . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch . ds L" "" . ds R" "" . ds C` "" . ds C' "" 'br\} .el\{\ . ds -- \|\(em\| . ds PI \(*p . ds L" `` . ds R" '' . ds C` . ds C' 'br\} .\" .\" Escape single quotes in literal strings from groff's Unicode transform. .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" .\" If the F register is >0, we'll generate index entries on stderr for .\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index .\" entries marked with X<> in POD. Of course, you'll have to process the .\" output yourself in some meaningful fashion. .\" .\" Avoid warning from groff about undefined register 'F'. .de IX .. .nr rF 0 .if \n(.g .if rF .nr rF 1 .if (\n(rF:(\n(.g==0)) \{\ . if \nF \{\ . de IX . tm Index:\\$1\t\\n%\t"\\$2" .. . if !\nF==2 \{\ . nr % 0 . nr F 2 . \} . \} .\} .rr rF .\" .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). .\" Fear. Run. Save yourself. No user-serviceable parts. . \" fudge factors for nroff and troff .if n \{\ . ds #H 0 . ds #V .8m . ds #F .3m . ds #[ \f1 . ds #] \fP .\} .if t \{\ . ds #H ((1u-(\\\\n(.fu%2u))*.13m) . ds #V .6m . ds #F 0 . ds #[ \& . ds #] \& .\} . \" simple accents for nroff and troff .if n \{\ . ds ' \& . ds ` \& . ds ^ \& . ds , \& . ds ~ ~ . ds / .\} .if t \{\ . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' .\} . \" troff and (daisy-wheel) nroff accents .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' .ds 8 \h'\*(#H'\(*b\h'-\*(#H' .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] .ds ae a\h'-(\w'a'u*4/10)'e .ds Ae A\h'-(\w'A'u*4/10)'E . \" corrections for vroff .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' . \" for low resolution devices (crt and lpr) .if \n(.H>23 .if \n(.V>19 \ \{\ . ds : e . ds 8 ss . ds o a . ds d- d\h'-1'\(ga . ds D- D\h'-1'\(hy . ds th \o'bp' . ds Th \o'LP' . ds ae ae . ds Ae AE .\} .rm #[ #] #H #V #F C .\" ======================================================================== .\" .IX Title "SPKAC 1" .TH SPKAC 1 "2023-09-11" "1.1.1w" "OpenSSL" .\" For nroff, turn off justification. Always turn off hyphenation; it makes .\" way too many mistakes in technical documents. .if n .ad l .nh .SH "NAME" openssl\-spkac, spkac \- SPKAC printing and generating utility .SH "SYNOPSIS" .IX Header "SYNOPSIS" \&\fBopenssl\fR \fBspkac\fR [\fB\-help\fR] [\fB\-in filename\fR] [\fB\-out filename\fR] [\fB\-key keyfile\fR] [\fB\-keyform PEM|DER|ENGINE\fR] [\fB\-passin arg\fR] [\fB\-challenge string\fR] [\fB\-pubkey\fR] [\fB\-spkac spkacname\fR] [\fB\-spksect section\fR] [\fB\-noout\fR] [\fB\-verify\fR] [\fB\-engine id\fR] .SH "DESCRIPTION" .IX Header "DESCRIPTION" The \fBspkac\fR command processes Netscape signed public key and challenge (\s-1SPKAC\s0) files. It can print out their contents, verify the signature and produce its own SPKACs from a supplied private key. .SH "OPTIONS" .IX Header "OPTIONS" .IP "\fB\-help\fR" 4 .IX Item "-help" Print out a usage message. .IP "\fB\-in filename\fR" 4 .IX Item "-in filename" This specifies the input filename to read from or standard input if this option is not specified. Ignored if the \fB\-key\fR option is used. .IP "\fB\-out filename\fR" 4 .IX Item "-out filename" Specifies the output filename to write to or standard output by default. .IP "\fB\-key keyfile\fR" 4 .IX Item "-key keyfile" Create an \s-1SPKAC\s0 file using the private key in \fBkeyfile\fR. The \&\fB\-in\fR, \fB\-noout\fR, \fB\-spksect\fR and \fB\-verify\fR options are ignored if present. .IP "\fB\-keyform PEM|DER|ENGINE\fR" 4 .IX Item "-keyform PEM|DER|ENGINE" Whether the key format is \s-1PEM, DER,\s0 or an engine-backed key. The default is \s-1PEM.\s0 .IP "\fB\-passin password\fR" 4 .IX Item "-passin password" The input file password source. For more information about the format of \fBarg\fR see \*(L"Pass Phrase Options\*(R" in \fBopenssl\fR\|(1). .IP "\fB\-challenge string\fR" 4 .IX Item "-challenge string" Specifies the challenge string if an \s-1SPKAC\s0 is being created. .IP "\fB\-spkac spkacname\fR" 4 .IX Item "-spkac spkacname" Allows an alternative name form the variable containing the \&\s-1SPKAC.\s0 The default is \*(L"\s-1SPKAC\*(R".\s0 This option affects both generated and input \s-1SPKAC\s0 files. .IP "\fB\-spksect section\fR" 4 .IX Item "-spksect section" Allows an alternative name form the section containing the \&\s-1SPKAC.\s0 The default is the default section. .IP "\fB\-noout\fR" 4 .IX Item "-noout" Don't output the text version of the \s-1SPKAC\s0 (not used if an \&\s-1SPKAC\s0 is being created). .IP "\fB\-pubkey\fR" 4 .IX Item "-pubkey" Output the public key of an \s-1SPKAC\s0 (not used if an \s-1SPKAC\s0 is being created). .IP "\fB\-verify\fR" 4 .IX Item "-verify" Verifies the digital signature on the supplied \s-1SPKAC.\s0 .IP "\fB\-engine id\fR" 4 .IX Item "-engine id" Specifying an engine (by its unique \fBid\fR string) will cause \fBspkac\fR to attempt to obtain a functional reference to the specified engine, thus initialising it if needed. The engine will then be set as the default for all available algorithms. .SH "EXAMPLES" .IX Header "EXAMPLES" Print out the contents of an \s-1SPKAC:\s0 .PP .Vb 1 \& openssl spkac \-in spkac.cnf .Ve .PP Verify the signature of an \s-1SPKAC:\s0 .PP .Vb 1 \& openssl spkac \-in spkac.cnf \-noout \-verify .Ve .PP Create an \s-1SPKAC\s0 using the challenge string \*(L"hello\*(R": .PP .Vb 1 \& openssl spkac \-key key.pem \-challenge hello \-out spkac.cnf .Ve .PP Example of an \s-1SPKAC,\s0 (long lines split up for clarity): .PP .Vb 6 \& SPKAC=MIG5MGUwXDANBgkqhkiG9w0BAQEFAANLADBIAkEA\e \& 1cCoq2Wa3Ixs47uI7FPVwHVIPDx5yso105Y6zpozam135a\e \& 8R0CpoRvkkigIyXfcCjiVi5oWk+6FfPaD03uPFoQIDAQAB\e \& FgVoZWxsbzANBgkqhkiG9w0BAQQFAANBAFpQtY/FojdwkJ\e \& h1bEIYuc2EeM2KHTWPEepWYeawvHD0gQ3DngSC75YCWnnD\e \& dq+NQ3F+X4deMx9AaEglZtULwV4= .Ve .SH "NOTES" .IX Header "NOTES" A created \s-1SPKAC\s0 with suitable \s-1DN\s0 components appended can be fed into the \fBca\fR utility. .PP SPKACs are typically generated by Netscape when a form is submitted containing the \fB\s-1KEYGEN\s0\fR tag as part of the certificate enrollment process. .PP The challenge string permits a primitive form of proof of possession of private key. By checking the \s-1SPKAC\s0 signature and a random challenge string some guarantee is given that the user knows the private key corresponding to the public key being certified. This is important in some applications. Without this it is possible for a previous \s-1SPKAC\s0 to be used in a \*(L"replay attack\*(R". .SH "SEE ALSO" .IX Header "SEE ALSO" \&\fBca\fR\|(1) .SH "COPYRIGHT" .IX Header "COPYRIGHT" Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. .PP Licensed under the OpenSSL license (the \*(L"License\*(R"). You may not use this file except in compliance with the License. You can obtain a copy in the file \s-1LICENSE\s0 in the source distribution or at .