Using pk12util enabless you to export certificates and keys from your internal database and import them into an internal or external PKCS #11 module. You can always export certificates and keys to your internal database, but most external tokens will not allow you to export certificates and keys. By default, pk12util uses certificate and key databases named cert8.db and key3.db.
Go to the server-root/alias directory containing the databases.
Add server-root/bin/proxy/admin/bin to your PATH.
Locate pk12util in server-root/bin/proxy/admin/bin.
Set the environment.
On UNIX:
setenv LD_LIBRARY_PATH/server-root/bin/proxy/lib:${LD_LIBRARY_PATH}
On Windows, add it to the PATH
LD_LIBRARY_PATH server-root/bin/proxy/bin
You can find the PATH for your computer listed under: server-root/proxy-admserv/start.
In a terminal window, type pk12util.
The options will be listed.
Perform the actions required.
For example, in UNIX type
pk12util -o certpk12 -n Server-Cert [-d /server/alias] [-P https-test-host]
Type the database password.
Type the pkcs12 password.