Skip to content

CLI Commands

Use this page to view the command options in one place.

Command map

Command Purpose Typical next step
paccor certgen Build or update a to-be-signed envelope from JSON inputs and certificate context. Run paccor assemble
paccor assemble Turn an envelope into a signed certificate or stub. Run paccor validate or paccor view
paccor validate Check signature, profile structure, and component matching. Use in CI or manufacturing checks
paccor view Print a compact human-readable summary of a certificate. Use during debugging or review

Global options

These options are accepted by each command:

Option Meaning
--log-level JUL logging level, such as FINE, FINER, INFO, or WARNING. FINE and more verbose levels also enable extra validation detail in validate.
--log-file Write logs to a file.
-q, --quiet Suppress normal output.
-h, --help Show command help.
-V, --version Print the version.

paccor certgen

Builds a JSON envelope that contains:

  • the certificate kind and specification version
  • the finalized TBS bytes when enough input is available
  • a serialized PlatformCertificateInformationModel
  • the signature AlgorithmIdentifier
  • If you omit --sig-profile, paccor infers the algorithm from --issuer-cert, or reuses the algorithm recorded in the envelope passed with --in. If neither is available, no signature algorithm is set and the TBS cannot be finalized.
  • Use Signing Algorithms to see the accepted --sig-profile values.

What you see when you type paccor certgen -h:

Usage: paccor certgen [-hqV] [--finalize] [--overwrite-in-place]
                      [-a=<notAfter>] [-b=<notBefore>] [-c=<componentsJson>]
                      [-e=<holderCert>] -f=<outJson> [--in=<inJson>]
                      [--in-platform-model=<platformInfoJson>]
                      [--kind=<certKind>] [--log-file=<logFile>]
                      [--log-level=<logLevel>] [-N=<serial>] [-p=<attrsJson>]
                      [-P=<issuerCert>] [--prev-pcert=<previousPlatformCert>]
                      [--sig-profile=<sigProfile>] [--subject-dn=<subjectDn>]
                      [--subject-key=<subjectKey>] [--type=<certType>]
                      [-x=<extJson>]
Generate Platform Certificate data
  -a, --not-after=<notAfter> yyyyMMdd
  -b, --not-before=<notBefore>
                             yyyyMMdd
  -c, --components-json=<componentsJson>
                             Hardware manifest components JSON file
  -e, --holder-cert=<holderCert>
                             Holder/Subject certificate file
  -f, --out=<outJson>        Model data and context in JSON. Can be given to
                               the assemble command
      --finalize             Validate model data and context prior to output
  -h, --help                 Show this help message and exit.
      --in=<inJson>          Existing to-be-signed data to merge from JSON
      --in-platform-model=<platformInfoJson>
                             Existing model data from JSON
      --kind, --cert-kind=<certKind>
                             Certificate output kind (AC, PKC)
      --log-file=<logFile>   Path to save rotating logs. If null or omitted,
                               file logging is disabled.
      --log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
                               WARNING, SEVERE, OFF
  -N, --serial=<serial>      Certificate serial number
      --overwrite-in-place   Allow in-place overwrite when --in equals --out.
  -p, --attributes-json=<attrsJson>
                             Attributes JSON file
  -P, --issuer-cert=<issuerCert>
                             Issuer certificate file
      --prev-pcert=<previousPlatformCert>
                             Single previous platform certificate used as the
                               V2.0 chain seed. Use
                               previousPlatformCertificates JSON for additional
                               entries.
  -q, --quiet                Suppress console logging.
      --sig-profile=<sigProfile>
                             Signature profile ID
      --subject-dn=<subjectDn>
                             Subject distinguished name for PKC output (for
                               example, CN=Platform,O=Example)
      --subject-key=<subjectKey>
                             Subject public key file (DER or PEM
                               SubjectPublicKeyInfo) for PKC output
      --type, --cert-type=<certType>
                             Platform certificate type (base, delta, rebase)
  -V, --version              Print version information and exit.
  -x, --extensions-json=<extJson>
                             Extensions JSON file

Example usage:

paccor certgen \
  --kind AC
  --issuer-cert TestCA.cert.example.pem \
  --holder-cert TCG_EK_ecc_p384_P-384_Test.pem \
  --attributes-json localhost-policyreference-v2.json \
  --components-json componentswithtraits.json \
  --extensions-json extentions.json \
  --sig-profile rsa-sha256 \
  --finalize \
  --out example-envelope.json

For PKC generation, --subject-key can provide a DER or PEM SubjectPublicKeyInfo directly, with --subject-dn supplying its X.500 subject name. The DN may instead come from a platform model supplied with --in-platform-model. These options are mutually exclusive with --holder-cert.

Delta and rebase certificates

Pass the certificate the new one builds on with --prev-pcert. It must name exactly one readable platform certificate. Use previousPlatformCertificates JSON for additional history.

certgen does not check the previous certificate's signature, because it may come from a different CA than --issuer-cert. Before issuing, check it with validate, using the CA that signed it:

paccor validate \
  --x509v2AttrCert example-cert.pem \
  --issuer-cert TestCA.cert.example.pem \
  --skip-component-validation

Add --trust-anchor and --crl to that command to also check the issuer's trust path and revocation.

paccor assemble

Consumes an envelope and produces the signed certificate. You must choose exactly one signing mode:

  • local private key with --local-key
  • PKCS#11 token with --pkcs11-module
  • remote signer with --remote-url
  • detached signature with --signature
  • See Signing Modes for sample usage of PKCS#11, remote, detached, and local key signature modes.

  • assemble will stop if the signature and issuer certificate do not match.

  • If the envelope does not yet contain final TBS data or an algorithm identifier, assemble can still write a stub instead of a final credential.

What you see when you type paccor assemble -h:

Usage: paccor assemble [-hqV] [--pem] -f=<outFile> -i=<inJson> [-k=<localKey>]
                       [--local-key-password=<localKeyPassword>]
                       [--local-key-password-file=<localKeyPasswordFile>]
                       [--log-file=<logFile>] [--log-level=<logLevel>]
                       [-P=<issuerCert>] [--pkcs11-key-alias=<pkcs11KeyAlias>]
                       [--pkcs11-key-id=<pkcs11KeyIdHex>]
                       [--pkcs11-module=<pkcs11Module>]
                       [--pkcs11-pin=<pkcs11Pin>]
                       [--pkcs11-pin-file=<pkcs11PinFile>]
                       [--pkcs11-slot=<pkcs11Slot>]
                       [--pkcs11-token-label=<pkcs11TokenLabel>]
                       [--remote-auth=<remoteAuth>]
                       [--remote-timeout=<remoteTimeoutMs>]
                       [--remote-url=<remoteUrl>]
                       [--sig-encoding=<sigEncoding>]
                       [--signature=<signatureB64>]
Assemble the Platform Certificate
  -f, --out=<outFile>
  -h, --help                 Show this help message and exit.
  -i, --in, --tbs=<inJson>   Input to-be-signed data from JSON
  -k, --local-key=<localKey> Sign locally with a private key file (PKCS#8,
                               PKCS#1, or PKCS#12)
      --local-key-password=<localKeyPassword>
                             Password for a PKCS#12 local key
      --local-key-password-file=<localKeyPasswordFile>
                             File containing the password for a PKCS#12 local
                               key
      --log-file=<logFile>   Path to save rotating logs. If null or omitted,
                               file logging is disabled.
      --log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
                               WARNING, SEVERE, OFF
  -P, --issuer-cert=<issuerCert>
                             Certificate containing the public key that signs
                               the input. Required for all signing modes
                               (detached, local, pkcs11, remote).
      --pem                  PEM output
      --pkcs11-key-alias=<pkcs11KeyAlias>
                             Alias/label of private key on token
      --pkcs11-key-id=<pkcs11KeyIdHex>
                             Hex ID of private key on token
      --pkcs11-module=<pkcs11Module>
                             Path to PKCS#11 module (.so/.dll)
      --pkcs11-pin=<pkcs11Pin>
                             PIN for the PKCS#11 token (alternatively use
                               PKCS11_PIN env var)
      --pkcs11-pin-file=<pkcs11PinFile>
                             File containing PIN for the PKCS#11 token
      --pkcs11-slot=<pkcs11Slot>
                             PKCS#11 slot list index (0 = first token)
      --pkcs11-token-label=<pkcs11TokenLabel>
                             PKCS#11 token label
  -q, --quiet                Suppress console logging.
      --remote-auth=<remoteAuth>
                             Remote signer auth descriptor, e.g., bearer:
                               <token> or header:Name=Value
      --remote-timeout=<remoteTimeoutMs>
                             Remote signer timeout ms
      --remote-url=<remoteUrl>
                             Remote signer URL
      --sig-encoding=<sigEncoding>
                             DER, P1363 (default: der)
      --signature=<signatureB64>
                             Detached signature (Base64)
  -V, --version              Print version information and exit.

Example usage:

paccor assemble \
  --in example-envelope.json \
  --out example-cert.pem \
  --pem \
  --local-key TestCA.private.example.pem \
  --issuer-cert TestCA.cert.example.pem

paccor validate

Validates a certificate against these groups of checks:

  • signature verification against --issuer-cert
  • issuer trust path, when --trust-anchor is given
  • revocation, when --crl is given
  • certificate profile/specification checks
  • component matching against expected JSON (--components-json)
  • For a delta or rebase certificate, pass previous platform certificates with --prev-pcert

Each check prints its own result line, followed by an overall result. The command exits 0 only when signature and component validation both pass, along with any profile, trust-anchor, or CRL checks that ran. Leaving out --components-json is a failure:

Component validation: FAILED (--components-json not provided)

To check a certificate without a components file, for example right after issuing it, pass --skip-component-validation. Components are then not checked, and the exit code reflects the remaining checks:

Component validation: SKIPPED (user requested to bypass)

--skip-component-validation cannot be combined with --components-json.

Component matching pairs every hardware component with a certificate component. For a delta or rebase certificate, pass the earlier certificates in the chain with --prev-pcert (repeatable, globs allowed). The base and deltas are applied in order to produce the expected component list. Every delta component must carry a status. A removed or modified entry must identify a component from the earlier certificates.

Previous platform certificates must be signed by --issuer-cert or by a certificate given with --trust-anchor. --trust-anchor also accepts intermediate CA certificates. For example, when the base certificate comes from an OEM sub-CA and the delta from a different sub-CA, pass the OEM sub-CA certificate and the shared root with --trust-anchor.

  • Use --component-matcher RAW only when you specifically need strict raw comparison rather than normalized matching. The default normalized matcher ignores case and extra whitespace in manufacturer and model, and treats values such as Unknown and N/A as empty.

What you see when you type paccor validate -h:

Usage: paccor validate [-hqV] [--skip-component-validation]
                       [-c=<componentsJson>]
                       [--component-matcher=<componentMatcherName>]
                       [--log-file=<logFile>] [--log-level=<logLevel>]
                       [-P=<signerFile>] -X=<platformCertFile>
                       [--crl=<crlList>]...
                       [--prev-pcert=<previousPlatformCertsList>]...
                       [--trust-anchor=<trustAnchorList>]...
Validate a platform certificate.
Exits 0 only when signature and component validation pass. Profile checks
always run, and trust-anchor and CRL checks run when their inputs are given.
Use --skip-component-validation to validate without a components file.
  -c, --components-json=<componentsJson>
                             Components JSON to verify against the certificate
                               components. Required unless
                               --skip-component-validation is given.
      --component-matcher=<componentMatcherName>
                             Component matcher: NORMALIZED (default) or RAW
      --crl=<crlList>        CRL file(s) for revocation checking. Repeatable.
                               Globs allowed.
  -h, --help                 Show this help message and exit.
      --log-file=<logFile>   Path to save rotating logs. If null or omitted,
                               file logging is disabled.
      --log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
                               WARNING, SEVERE, OFF
  -P, --issuer-cert, --publicKeyCert=<signerFile>
                             Signer certificate file
      --prev-pcert=<previousPlatformCertsList>
                             Previous platform certificate file(s). Repeatable.
                               Globs allowed.
  -q, --quiet                Suppress console logging.
      --skip-component-validation
                             Do not validate components. The exit code then
                               reflects the remaining checks only.
      --trust-anchor=<trustAnchorList>
                             Trust anchor(s) and intermediate CA certificates.
                               Repeatable. Globs allowed. If provided, the
                               issuer cert must be self-signed or chain to a
                               self-signed trust anchor. Previous platform
                               certificates may be signed by --issuer-cert or
                               by any certificate given here that chains to a
                               self-signed anchor.
  -V, --version              Print version information and exit.
  -X, --x509v2AttrCert, --pkcPlatformCert=<platformCertFile>
                             Platform certificate file

Example usage:

paccor validate \
  --x509v2AttrCert example-cert.pem \
  --issuer-cert TestCA.cert.example.pem \
  --components-json componentswithtraits.json

Validating a delta certificate against its base:

paccor validate \
  --x509v2AttrCert example-delta.pem \
  --issuer-cert TestCA.cert.example.pem \
  --prev-pcert example-cert.pem \
  --components-json current-components.json

paccor view

Prints a compact summary of the certificate contents without validating against external inputs.

The output includes the certificate kind, certificate type, resolved spec version, holder or subject, issuer, serial, platform specification, platform facts, component count, and counts for previous certificates and cryptographic anchors.

What you see when you type paccor view -h:

Usage: paccor view [-hqV] [--log-file=<logFile>] [--log-level=<logLevel>]
                   -X=<platformCertFile>
Display a summary of a platform certificate
  -h, --help                 Show this help message and exit.
      --log-file=<logFile>   Path to save rotating logs. If null or omitted,
                               file logging is disabled.
      --log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
                               WARNING, SEVERE, OFF
  -q, --quiet                Suppress console logging.
  -V, --version              Print version information and exit.
  -X, --certificate, --x509v2AttrCert, --pkcPlatformCert=<platformCertFile>
                             Platform certificate file

Example usage:

paccor view --certificate example-cert.pem

paccor

What you see when you type paccor -h:

Usage: paccor [-hqV] [--log-file=<logFile>] [--log-level=<logLevel>] [COMMAND]
Platform Certificate Creator CLI
  -h, --help                 Show this help message and exit.
      --log-file=<logFile>   Path to save rotating logs. If null or omitted,
                               file logging is disabled.
      --log-level=<logLevel> Options: ALL, FINEST, FINER, FINE, CONFIG, INFO,
                               WARNING, SEVERE, OFF
  -q, --quiet                Suppress console logging.
  -V, --version              Print version information and exit.
Commands:
  certgen   Generate Platform Certificate data
  assemble  Assemble the Platform Certificate
  validate  Validate a platform certificate.
  view      Display a summary of a platform certificate