Skip to content

PKI Server Instance External Certificate CLI

Endi S. Dewata edited this page Mar 27, 2024 · 3 revisions

Overview

The pki-server instance-externalcert commands can be used to manage external certificates in PKI server’s NSS database.

Configuration

The list of external certificates is stored in /var/lib/pki/pki-tomcat/conf/external_certs.conf, for example:

0.nickname=third_party_ca
0.token=internal

Adding External Certificate

$ pki-server instance-externalcert-add \
    --cert-file third_party_ca.crt \
    --trust-args=CT,C,C \
    --nickname third_party_ca

Removing External Certificate

$ pki-server instance-externalcert-del \
    --nickname third_party_ca
Clone this wiki locally