CLI Commands¶
Use this page to view the command options in one place.
Command map¶
| Command | Purpose | Typical next step |
|---|---|---|
paccor certgen |
Build or update a to-be-signed envelope from JSON inputs and certificate context. | Run paccor assemble |
paccor assemble |
Turn an envelope into a signed certificate or stub. | Run paccor validate or paccor view |
paccor validate |
Check signature, profile structure, and component matching. | Use in CI or manufacturing checks |
paccor view |
Print a compact human-readable summary of a certificate. | Use during debugging or review |
Global options¶
These options are accepted by each command:
| Option | Meaning |
|---|---|
--log-level |
JUL logging level, such as FINE, FINER, INFO, or WARNING. FINE and more verbose levels also enable extra validation detail in validate. |
--log-file |
Write logs to a file. |
-q, --quiet |
Suppress normal output. |
-h, --help |
Show command help. |
-V, --version |
Print the version. |
paccor certgen¶
Builds a JSON envelope that contains:
- the certificate kind and specification version
- the finalized TBS bytes when enough input is available
- a serialized
PlatformCertificateInformationModel - the signature
AlgorithmIdentifier - If you omit
--sig-profile, paccor infers the algorithm from--issuer-cert, or reuses the algorithm recorded in the envelope passed with--in. If neither is available, no signature algorithm is set and the TBS cannot be finalized. - Use Signing Algorithms to see the accepted
--sig-profilevalues.
What you see when you type paccor certgen -h:
Usage: paccor certgen [-hqV] [--finalize] [--overwrite-in-place]
[-a=<notAfter>] [-b=<notBefore>] [-c=<componentsJson>]
[-e=<holderCert>] -f=<outJson> [--in=<inJson>]
[--in-platform-model=<platformInfoJson>]
[--kind=<certKind>] [--log-file=<logFile>]
[--log-level=<logLevel>] [-N=<serial>] [-p=<attrsJson>]
[-P=<issuerCert>] [--prev-pcert=<previousPlatformCert>]
[--sig-profile=<sigProfile>] [--subject-dn=<subjectDn>]
[--subject-key=<subjectKey>] [--type=<certType>]
[-x=<extJson>]
Generate Platform Certificate data
-a, --not-after=<notAfter> yyyyMMdd
-b, --not-before=<notBefore>
yyyyMMdd
-c, --components-json=<componentsJson>
Hardware manifest components JSON file
-e, --holder-cert=<holderCert>
Holder/Subject certificate file
-f, --out=<outJson> Model data and context in JSON. Can be given to
the assemble command
--finalize Validate model data and context prior to output
-h, --help Show this help message and exit.
--in=<inJson> Existing to-be-signed data to merge from JSON
--in-platform-model=<platformInfoJson>
Existing model data from JSON
--kind, --cert-kind=<certKind>
Certificate output kind (AC, PKC)
--log-file=<logFile> Path to save rotating logs. If null or omitted,
file logging is disabled.
--log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
WARNING, SEVERE, OFF
-N, --serial=<serial> Certificate serial number
--overwrite-in-place Allow in-place overwrite when --in equals --out.
-p, --attributes-json=<attrsJson>
Attributes JSON file
-P, --issuer-cert=<issuerCert>
Issuer certificate file
--prev-pcert=<previousPlatformCert>
Single previous platform certificate used as the
V2.0 chain seed. Use
previousPlatformCertificates JSON for additional
entries.
-q, --quiet Suppress console logging.
--sig-profile=<sigProfile>
Signature profile ID
--subject-dn=<subjectDn>
Subject distinguished name for PKC output (for
example, CN=Platform,O=Example)
--subject-key=<subjectKey>
Subject public key file (DER or PEM
SubjectPublicKeyInfo) for PKC output
--type, --cert-type=<certType>
Platform certificate type (base, delta, rebase)
-V, --version Print version information and exit.
-x, --extensions-json=<extJson>
Extensions JSON file
Example usage:
paccor certgen \
--kind AC
--issuer-cert TestCA.cert.example.pem \
--holder-cert TCG_EK_ecc_p384_P-384_Test.pem \
--attributes-json localhost-policyreference-v2.json \
--components-json componentswithtraits.json \
--extensions-json extentions.json \
--sig-profile rsa-sha256 \
--finalize \
--out example-envelope.json
For PKC generation, --subject-key can provide a DER or PEM SubjectPublicKeyInfo directly, with --subject-dn supplying its X.500 subject name. The DN may instead come from a platform model supplied with --in-platform-model. These options are mutually exclusive with --holder-cert.
Delta and rebase certificates¶
Pass the certificate the new one builds on with --prev-pcert. It must name exactly one readable platform certificate. Use previousPlatformCertificates JSON for additional history.
certgen does not check the previous certificate's signature, because it may come from a different CA than --issuer-cert. Before issuing, check it with validate, using the CA that signed it:
paccor validate \
--x509v2AttrCert example-cert.pem \
--issuer-cert TestCA.cert.example.pem \
--skip-component-validation
Add --trust-anchor and --crl to that command to also check the issuer's trust path and revocation.
paccor assemble¶
Consumes an envelope and produces the signed certificate. You must choose exactly one signing mode:
- local private key with
--local-key - PKCS#11 token with
--pkcs11-module - remote signer with
--remote-url - detached signature with
--signature -
See Signing Modes for sample usage of PKCS#11, remote, detached, and local key signature modes.
-
assemblewill stop if the signature and issuer certificate do not match. - If the envelope does not yet contain final TBS data or an algorithm identifier,
assemblecan still write a stub instead of a final credential.
What you see when you type paccor assemble -h:
Usage: paccor assemble [-hqV] [--pem] -f=<outFile> -i=<inJson> [-k=<localKey>]
[--local-key-password=<localKeyPassword>]
[--local-key-password-file=<localKeyPasswordFile>]
[--log-file=<logFile>] [--log-level=<logLevel>]
[-P=<issuerCert>] [--pkcs11-key-alias=<pkcs11KeyAlias>]
[--pkcs11-key-id=<pkcs11KeyIdHex>]
[--pkcs11-module=<pkcs11Module>]
[--pkcs11-pin=<pkcs11Pin>]
[--pkcs11-pin-file=<pkcs11PinFile>]
[--pkcs11-slot=<pkcs11Slot>]
[--pkcs11-token-label=<pkcs11TokenLabel>]
[--remote-auth=<remoteAuth>]
[--remote-timeout=<remoteTimeoutMs>]
[--remote-url=<remoteUrl>]
[--sig-encoding=<sigEncoding>]
[--signature=<signatureB64>]
Assemble the Platform Certificate
-f, --out=<outFile>
-h, --help Show this help message and exit.
-i, --in, --tbs=<inJson> Input to-be-signed data from JSON
-k, --local-key=<localKey> Sign locally with a private key file (PKCS#8,
PKCS#1, or PKCS#12)
--local-key-password=<localKeyPassword>
Password for a PKCS#12 local key
--local-key-password-file=<localKeyPasswordFile>
File containing the password for a PKCS#12 local
key
--log-file=<logFile> Path to save rotating logs. If null or omitted,
file logging is disabled.
--log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
WARNING, SEVERE, OFF
-P, --issuer-cert=<issuerCert>
Certificate containing the public key that signs
the input. Required for all signing modes
(detached, local, pkcs11, remote).
--pem PEM output
--pkcs11-key-alias=<pkcs11KeyAlias>
Alias/label of private key on token
--pkcs11-key-id=<pkcs11KeyIdHex>
Hex ID of private key on token
--pkcs11-module=<pkcs11Module>
Path to PKCS#11 module (.so/.dll)
--pkcs11-pin=<pkcs11Pin>
PIN for the PKCS#11 token (alternatively use
PKCS11_PIN env var)
--pkcs11-pin-file=<pkcs11PinFile>
File containing PIN for the PKCS#11 token
--pkcs11-slot=<pkcs11Slot>
PKCS#11 slot list index (0 = first token)
--pkcs11-token-label=<pkcs11TokenLabel>
PKCS#11 token label
-q, --quiet Suppress console logging.
--remote-auth=<remoteAuth>
Remote signer auth descriptor, e.g., bearer:
<token> or header:Name=Value
--remote-timeout=<remoteTimeoutMs>
Remote signer timeout ms
--remote-url=<remoteUrl>
Remote signer URL
--sig-encoding=<sigEncoding>
DER, P1363 (default: der)
--signature=<signatureB64>
Detached signature (Base64)
-V, --version Print version information and exit.
Example usage:
paccor assemble \
--in example-envelope.json \
--out example-cert.pem \
--pem \
--local-key TestCA.private.example.pem \
--issuer-cert TestCA.cert.example.pem
paccor validate¶
Validates a certificate against these groups of checks:
- signature verification against
--issuer-cert - issuer trust path, when
--trust-anchoris given - revocation, when
--crlis given - certificate profile/specification checks
- component matching against expected JSON (
--components-json) - For a delta or rebase certificate, pass previous platform certificates with
--prev-pcert
Each check prints its own result line, followed by an overall result. The command exits 0 only when signature and component validation both pass, along with any profile, trust-anchor, or CRL checks that ran. Leaving out --components-json is a failure:
To check a certificate without a components file, for example right after issuing it, pass --skip-component-validation. Components are then not checked, and the exit code reflects the remaining checks:
--skip-component-validation cannot be combined with --components-json.
Component matching pairs every hardware component with a certificate component. For a delta or rebase certificate, pass the earlier certificates in the chain with --prev-pcert (repeatable, globs allowed). The base and deltas are applied in order to produce the expected component list. Every delta component must carry a status. A removed or modified entry must identify a component from the earlier certificates.
Previous platform certificates must be signed by --issuer-cert or by a certificate given with --trust-anchor. --trust-anchor also accepts intermediate CA certificates. For example, when the base certificate comes from an OEM sub-CA and the delta from a different sub-CA, pass the OEM sub-CA certificate and the shared root with --trust-anchor.
- Use
--component-matcher RAWonly when you specifically need strict raw comparison rather than normalized matching. The default normalized matcher ignores case and extra whitespace in manufacturer and model, and treats values such asUnknownandN/Aas empty.
What you see when you type paccor validate -h:
Usage: paccor validate [-hqV] [--skip-component-validation]
[-c=<componentsJson>]
[--component-matcher=<componentMatcherName>]
[--log-file=<logFile>] [--log-level=<logLevel>]
[-P=<signerFile>] -X=<platformCertFile>
[--crl=<crlList>]...
[--prev-pcert=<previousPlatformCertsList>]...
[--trust-anchor=<trustAnchorList>]...
Validate a platform certificate.
Exits 0 only when signature and component validation pass. Profile checks
always run, and trust-anchor and CRL checks run when their inputs are given.
Use --skip-component-validation to validate without a components file.
-c, --components-json=<componentsJson>
Components JSON to verify against the certificate
components. Required unless
--skip-component-validation is given.
--component-matcher=<componentMatcherName>
Component matcher: NORMALIZED (default) or RAW
--crl=<crlList> CRL file(s) for revocation checking. Repeatable.
Globs allowed.
-h, --help Show this help message and exit.
--log-file=<logFile> Path to save rotating logs. If null or omitted,
file logging is disabled.
--log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
WARNING, SEVERE, OFF
-P, --issuer-cert, --publicKeyCert=<signerFile>
Signer certificate file
--prev-pcert=<previousPlatformCertsList>
Previous platform certificate file(s). Repeatable.
Globs allowed.
-q, --quiet Suppress console logging.
--skip-component-validation
Do not validate components. The exit code then
reflects the remaining checks only.
--trust-anchor=<trustAnchorList>
Trust anchor(s) and intermediate CA certificates.
Repeatable. Globs allowed. If provided, the
issuer cert must be self-signed or chain to a
self-signed trust anchor. Previous platform
certificates may be signed by --issuer-cert or
by any certificate given here that chains to a
self-signed anchor.
-V, --version Print version information and exit.
-X, --x509v2AttrCert, --pkcPlatformCert=<platformCertFile>
Platform certificate file
Example usage:
paccor validate \
--x509v2AttrCert example-cert.pem \
--issuer-cert TestCA.cert.example.pem \
--components-json componentswithtraits.json
Validating a delta certificate against its base:
paccor validate \
--x509v2AttrCert example-delta.pem \
--issuer-cert TestCA.cert.example.pem \
--prev-pcert example-cert.pem \
--components-json current-components.json
paccor view¶
Prints a compact summary of the certificate contents without validating against external inputs.
The output includes the certificate kind, certificate type, resolved spec version, holder or subject, issuer, serial, platform specification, platform facts, component count, and counts for previous certificates and cryptographic anchors.
What you see when you type paccor view -h:
Usage: paccor view [-hqV] [--log-file=<logFile>] [--log-level=<logLevel>]
-X=<platformCertFile>
Display a summary of a platform certificate
-h, --help Show this help message and exit.
--log-file=<logFile> Path to save rotating logs. If null or omitted,
file logging is disabled.
--log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
WARNING, SEVERE, OFF
-q, --quiet Suppress console logging.
-V, --version Print version information and exit.
-X, --certificate, --x509v2AttrCert, --pkcPlatformCert=<platformCertFile>
Platform certificate file
Example usage:
paccor¶
What you see when you type paccor -h:
Usage: paccor [-hqV] [--log-file=<logFile>] [--log-level=<logLevel>] [COMMAND]
Platform Certificate Creator CLI
-h, --help Show this help message and exit.
--log-file=<logFile> Path to save rotating logs. If null or omitted,
file logging is disabled.
--log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
WARNING, SEVERE, OFF
-q, --quiet Suppress console logging.
-V, --version Print version information and exit.
Commands:
certgen Generate Platform Certificate data
assemble Assemble the Platform Certificate
validate Validate a platform certificate.
view Display a summary of a platform certificate