Bundle a CRL and Certificates into PKCS#7 with OpenSSL
You will create a PKCS#7 structure containing a certificate revocation list (CRL), one or more certificates, or both. The result can be PEM text or DER binary, and you will inspect it afterwards rather than trusting a successful file write. Allow about ten minutes if the input files already exist.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide covers the openssl crl2pkcs7 command supplied by the Debian openssl package version 3.0.13-0ubuntu3.15. The local manpage is dated 18 August 2026. On this machine, /usr/bin/openssl reports OpenSSL 3.0.13. The interactive shell may resolve a different OpenSSL binary first, so check yours before relying on the examples.
1. Check the binary and input files
Start with read-only checks. No command in this workflow normally needs sudo; the files should be readable by your account and the destination directory should be writable by it.
$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
$ dpkg-query -W -f='${Package} ${Version}\n' openssl
openssl 3.0.13-0ubuntu3.15
$ test -r /path/to/crl.pem && echo 'CRL is readable'
CRL is readable
$ test -r /path/to/certificates.pem && echo 'certificates are readable'
certificates are readable
The command name is openssl, followed by the subcommand crl2pkcs7. If you need to reproduce the packaged behaviour described here, call /usr/bin/openssl explicitly. A PEM certificate file can contain one or many certificates. The -certfile option may be repeated for separate files.
Checkpoint
Identify the exact CRL and certificate files you intend to bundle. Do not substitute a certificate for the CRL: the input supplied with -in is parsed as a CRL.
2. Create a PEM bundle with the CRL
The ordinary case reads a PEM CRL, adds certificates from a PEM file, and writes a PEM PKCS#7 object. The output is a certificate container, not a signed message: it has no signers.
$ openssl crl2pkcs7 \
-in /path/to/crl.pem \
-certfile /path/to/certificates.pem \
-out /path/to/bundle.p7b
The default input format, output format, and CRL handling are all PEM. The command writes no progress message on success. Verify that the destination is non-empty and ask the separate pkcs7 command to print the certificates it found:
$ test -s /path/to/bundle.p7b && echo 'bundle written'
bundle written
$ openssl pkcs7 -in /path/to/bundle.p7b -noout -print_certs
subject=CN = Example intermediate CA
issuer=CN = Example root CA
Your subject and issuer lines will differ. The listing confirms certificates, but it does not prove that the CRL contains the entries or that the certificates form a trusted chain. Those are separate validation tasks.
3. Add certificates from more than one file
Repeat -certfile when the certificates are stored separately. This is useful when a leaf certificate and CA certificates come from different sources.
$ openssl crl2pkcs7 \
-in /path/to/crl.pem \
-certfile /path/to/server.pem \
-certfile /path/to/intermediate.pem \
-certfile /path/to/root.pem \
-out /path/to/server-chain.p7b
$ openssl pkcs7 -in /path/to/server-chain.p7b -noout -print_certs
All certificates read by -certfile are added. The command does not use those files to verify a chain, and it does not reorder or repair a broken certificate collection for you. Keep the source files unchanged until the bundle has been checked by its consumer.
4. Produce DER instead of PEM
Use -outform DER when the receiving system expects binary DER. This changes the encoding of the PKCS#7 object, not the certificates selected for it.
$ openssl crl2pkcs7 \
-in /path/to/crl.pem \
-certfile /path/to/certificates.pem \
-outform DER \
-out /path/to/bundle.p7b.der
$ file /path/to/bundle.p7b.der
/path/to/bundle.p7b.der: DER Encoded PKCS#7 Signed Data
$ openssl pkcs7 -inform DER -in /path/to/bundle.p7b.der -noout -print_certs
Do not inspect a DER file in a text editor. It is binary and may contain bytes that a terminal interprets as control characters. The file result and the pkcs7 listing are useful format checks.
5. Make a certificate-only structure
Use -nocrl when the output must contain certificates without a CRL. With this option, the command does not read a CRL from -in. You can omit -in altogether.
$ openssl crl2pkcs7 \
-nocrl \
-certfile /path/to/newcert.pem \
-certfile /path/to/ca-cert.pem \
-outform DER \
-out /path/to/certificates.p7b
$ openssl pkcs7 -inform DER -in /path/to/certificates.p7b -noout -print_certs
subject=CN = Example user
issuer=CN = Example CA
This is the safest mode for testing the command with certificate files alone. The generated structure is still PKCS#7 signed data with no signers; it is not a signature and does not establish trust by itself.
6. Protect an existing output file
OpenSSL opens the path given to -out for writing. Treat an existing bundle as valuable until the replacement has passed inspection. Write to a new name first, then replace the old file only when you have checked the result.
$ openssl crl2pkcs7 \
-in /path/to/crl.pem \
-certfile /path/to/certificates.pem \
-out /path/to/bundle.p7b.new
$ test -s /path/to/bundle.p7b.new
$ openssl pkcs7 -in /path/to/bundle.p7b.new -noout -print_certs
$ mv /path/to/bundle.p7b.new /path/to/bundle.p7b
The mv step changes state and may replace the old bundle. If conversion or inspection fails, leave the original in place and remove the incomplete .new file after checking its path carefully. Do not use a broad wildcard for cleanup.
7. Diagnose the common failures
An error about opening the input usually means the path, permissions, or format is wrong. Check the file without changing it:
$ ls -l /path/to/crl.pem /path/to/certificates.pem
$ openssl crl -in /path/to/crl.pem -noout -issuer -lastupdate -nextupdate
If the CRL is DER, add -inform DER to crl2pkcs7. The -inform option describes the CRL supplied with -in; it does not describe the certificate files supplied with -certfile, which the command expects in PEM format.
If a consumer rejects the output, check whether it expects PEM or DER and whether it expects a CRL. Use matching -inform and -outform values, then inspect the result with openssl pkcs7. A successful conversion only says that OpenSSL accepted the input and wrote a PKCS#7 structure. It does not validate policy, trust, revocation freshness, or the recipient's MIME handling.
Done means
- The selected OpenSSL binary and package version are known.
- The CRL input format matches
-inform, and certificate sources are readable PEM files. - The bundle is written in the PEM or DER format required by its consumer.
openssl pkcs7can read the output and print its certificates.- An existing output was not overwritten until the replacement passed inspection.