Home / Alt manpages / openssl-crl2pkcs7(1ssl)

  • openssl-crl2pkcs7(1ssl)
  • OpenSSL command
  • linux

Bundle a CRL and Certificates into PKCS#7 with OpenSSL

You will create a PKCS#7 structure containing a certificate revocation list (CRL), one or more certificates, or both. The result can be PEM text or DER binary, and you will inspect it afterwards rather than trusting a successful file write. Allow about ten minutes if the input files already exist.

This guide covers the openssl crl2pkcs7 command supplied by the Debian openssl package version 3.0.13-0ubuntu3.15. The local manpage is dated 18 August 2026. On this machine, /usr/bin/openssl reports OpenSSL 3.0.13. The interactive shell may resolve a different OpenSSL binary first, so check yours before relying on the examples.

1. Check the binary and input files

Start with read-only checks. No command in this workflow normally needs sudo; the files should be readable by your account and the destination directory should be writable by it.

$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
$ dpkg-query -W -f='${Package} ${Version}\n' openssl
openssl 3.0.13-0ubuntu3.15
$ test -r /path/to/crl.pem && echo 'CRL is readable'
CRL is readable
$ test -r /path/to/certificates.pem && echo 'certificates are readable'
certificates are readable

The command name is openssl, followed by the subcommand crl2pkcs7. If you need to reproduce the packaged behaviour described here, call /usr/bin/openssl explicitly. A PEM certificate file can contain one or many certificates. The -certfile option may be repeated for separate files.

Checkpoint

Identify the exact CRL and certificate files you intend to bundle. Do not substitute a certificate for the CRL: the input supplied with -in is parsed as a CRL.

2. Create a PEM bundle with the CRL

The ordinary case reads a PEM CRL, adds certificates from a PEM file, and writes a PEM PKCS#7 object. The output is a certificate container, not a signed message: it has no signers.

$ openssl crl2pkcs7 \
    -in /path/to/crl.pem \
    -certfile /path/to/certificates.pem \
    -out /path/to/bundle.p7b

The default input format, output format, and CRL handling are all PEM. The command writes no progress message on success. Verify that the destination is non-empty and ask the separate pkcs7 command to print the certificates it found:

$ test -s /path/to/bundle.p7b && echo 'bundle written'
bundle written
$ openssl pkcs7 -in /path/to/bundle.p7b -noout -print_certs
subject=CN = Example intermediate CA
issuer=CN = Example root CA

Your subject and issuer lines will differ. The listing confirms certificates, but it does not prove that the CRL contains the entries or that the certificates form a trusted chain. Those are separate validation tasks.

3. Add certificates from more than one file

Repeat -certfile when the certificates are stored separately. This is useful when a leaf certificate and CA certificates come from different sources.

$ openssl crl2pkcs7 \
    -in /path/to/crl.pem \
    -certfile /path/to/server.pem \
    -certfile /path/to/intermediate.pem \
    -certfile /path/to/root.pem \
    -out /path/to/server-chain.p7b
$ openssl pkcs7 -in /path/to/server-chain.p7b -noout -print_certs

All certificates read by -certfile are added. The command does not use those files to verify a chain, and it does not reorder or repair a broken certificate collection for you. Keep the source files unchanged until the bundle has been checked by its consumer.

4. Produce DER instead of PEM

Use -outform DER when the receiving system expects binary DER. This changes the encoding of the PKCS#7 object, not the certificates selected for it.

$ openssl crl2pkcs7 \
    -in /path/to/crl.pem \
    -certfile /path/to/certificates.pem \
    -outform DER \
    -out /path/to/bundle.p7b.der
$ file /path/to/bundle.p7b.der
/path/to/bundle.p7b.der: DER Encoded PKCS#7 Signed Data
$ openssl pkcs7 -inform DER -in /path/to/bundle.p7b.der -noout -print_certs

Do not inspect a DER file in a text editor. It is binary and may contain bytes that a terminal interprets as control characters. The file result and the pkcs7 listing are useful format checks.

5. Make a certificate-only structure

Use -nocrl when the output must contain certificates without a CRL. With this option, the command does not read a CRL from -in. You can omit -in altogether.

$ openssl crl2pkcs7 \
    -nocrl \
    -certfile /path/to/newcert.pem \
    -certfile /path/to/ca-cert.pem \
    -outform DER \
    -out /path/to/certificates.p7b
$ openssl pkcs7 -inform DER -in /path/to/certificates.p7b -noout -print_certs
subject=CN = Example user
issuer=CN = Example CA

This is the safest mode for testing the command with certificate files alone. The generated structure is still PKCS#7 signed data with no signers; it is not a signature and does not establish trust by itself.

6. Protect an existing output file

OpenSSL opens the path given to -out for writing. Treat an existing bundle as valuable until the replacement has passed inspection. Write to a new name first, then replace the old file only when you have checked the result.

$ openssl crl2pkcs7 \
    -in /path/to/crl.pem \
    -certfile /path/to/certificates.pem \
    -out /path/to/bundle.p7b.new
$ test -s /path/to/bundle.p7b.new
$ openssl pkcs7 -in /path/to/bundle.p7b.new -noout -print_certs
$ mv /path/to/bundle.p7b.new /path/to/bundle.p7b

The mv step changes state and may replace the old bundle. If conversion or inspection fails, leave the original in place and remove the incomplete .new file after checking its path carefully. Do not use a broad wildcard for cleanup.

7. Diagnose the common failures

An error about opening the input usually means the path, permissions, or format is wrong. Check the file without changing it:

$ ls -l /path/to/crl.pem /path/to/certificates.pem
$ openssl crl -in /path/to/crl.pem -noout -issuer -lastupdate -nextupdate

If the CRL is DER, add -inform DER to crl2pkcs7. The -inform option describes the CRL supplied with -in; it does not describe the certificate files supplied with -certfile, which the command expects in PEM format.

If a consumer rejects the output, check whether it expects PEM or DER and whether it expects a CRL. Use matching -inform and -outform values, then inspect the result with openssl pkcs7. A successful conversion only says that OpenSSL accepted the input and wrote a PKCS#7 structure. It does not validate policy, trust, revocation freshness, or the recipient's MIME handling.

Done means

  • The selected OpenSSL binary and package version are known.
  • The CRL input format matches -inform, and certificate sources are readable PEM files.
  • The bundle is written in the PEM or DER format required by its consumer.
  • openssl pkcs7 can read the output and print its certificates.
  • An existing output was not overwritten until the replacement passed inspection.