![]() |
![]() |
p11-kit | ![]() |
---|
The trust module provides system certificate anchors, blacklists and other trust policy to crypto libraries applications. This information is exposed as PKCS#11 objects.
The trust module loads certificates and trust policy information from preconfigured directories and allows them to be looked up via PKCS#11. The directories can be determined with using the following commands:
System Anchors: certificates in these locations are automatically treated as certificate authority anchors unless they contain information that prevents that. To check which locations are being used, run the following command:
$ pkg-config --variable p11_system_anchors p11-kit-1 /etc/pki/tls/certs/ca-bundle.trust.crt:/etc/pki/tls/anchors
System Certificates: certificates in these locations are not treated as anchors, but simply made available through the module. To find out which directory is used, run the following command:
$ pkg-config --variable p11_system_certificates p11-kit-1 /etc/pki/tls/other-certs
Files in the following formats are supported for loading by the trust policy module:
X.509 certificates |
X.509 certificates in raw DER format. |
OpenSSL trust certificates |
OpenSSL specific certificates in PEM format
that contain trust information. These have a
|