Sun Java System Application Server Enterprise Edition 8.1 2005Q2 Administration Guide

Using the certutil Utility

The certificate database tool, certutil, is an NSS command-line utility that can create and modify the Netscape Communicator cert8.db and key3.db database files. It can also list, generate, modify, or delete certificates within the cert8.db file and create or change the password, generate new public and private key pairs, display the contents of the key database, or delete key pairs within the key3.db file.

The key and certificate management process generally begins with creating keys in the key database, then generating and managing certificates in the certificate database. The following document discusses certificate and key database management with NSS, including the syntax for the certutil utility:

Each of the items in the list below gives an example using NSS and JSSE security tools to create and/or manage certificates.