Home / Alt manpages / secutil(1)

  • secutil(1)
  • User command
  • linux

Inspect a Mono Assembly's Strong Name with secutil

You will use secutil to read the strong-name identity embedded in a Mono assembly, then select output that can be reused in C#, C++ or Visual Basic. The examples only read the assembly. Allow about ten minutes if Mono is already installed.

This guide uses Mono SecUtil 6.8.0.105 from the mono-devel package installed on this machine. The local manual page documents the strong-name and X.509 operations, but the installed program also accepts -hex in its help output. Treat the installed version as the authority for the examples below.

1. Check the command and choose an assembly

Start by confirming which executable will run and locating a readable managed assembly. This is an unprivileged, read-only check:

$ command -v secutil
/usr/bin/secutil
$ test -r /usr/lib/mono/4.5/mscorlib.dll && echo readable
readable

Replace /usr/lib/mono/4.5/mscorlib.dll with the path to the assembly you actually need to inspect. Do not use a path copied from a package listing without checking that it exists on this host.

Checkpoint: the input should be an assembly file, not a source file, package archive or directory. SecUtil does not modify it, so there is no undo step for this guide.

2. Print the strong-name information

Use -s, or its long form -strongname, followed by the assembly path:

$ secutil -s /usr/lib/mono/4.5/mscorlib.dll
Mono SecUtil - version 6.8.0.105
Extract strongname and X509 certificates from assemblies.
Copyright 2002, 2003 Motus Technologies. Copyright 2004-2008 Novell. BSD licensed.

PublicKey =
{ 0, 0, 0, 0, 0, 0, 0, 0, 4, 0, 0, 0, 0, 0, 0, 0 }
Name =
mscorlib
Version =
4.0.0.0
Success

The exact public key depends on the input. The useful fields are the public key, assembly name and version. Success is the tool's completion message, not a claim that the assembly is trustworthy. A strong name identifies an assembly and helps detect replacement; it is not a substitute for a trusted distribution channel or a signature policy.

Verify the process result immediately if a script will rely on it:

$ secutil -s /usr/lib/mono/4.5/mscorlib.dll > /tmp/mscorlib-secutil.txt
$ printf '%s\n' "secutil status: $?"
secutil status: 0

3. Select source-code-friendly formatting

The manual describes decimal arrays as the default and C/C++/C# formatting as the default language mode. The installed parser expects the formatting option before the operation, so put -v or -c before -s when combining them:

$ secutil -v -s /usr/lib/mono/4.5/mscorlib.dll
PublicKey =
( 0, 0, 0, 0, 0, 0, 0, 0, 4, 0, 0, 0, 0, 0, 0, 0 )
Name =
mscorlib
Version =
4.0.0.0
Success
$ secutil -c -s /usr/lib/mono/4.5/mscorlib.dll | sed -n '1,12p'
Mono SecUtil - version 6.8.0.105
Extract strongname and X509 certificates from assemblies.

-v and -vbmode select Visual Basic-friendly output. -c and -cmode select C, C++ or C#-friendly output. -a and -array select a decimal array. Keep the output as text if another build step will consume it; do not treat it as a generated replacement for the assembly.

4. Try certificate extraction only when a certificate is expected

Use -x, or -x509certificate, for an X.509 Authenticode certificate:

$ secutil -x /path/to/signed-assembly.dll
Mono SecUtil - version 6.8.0.105
Extract strongname and X509 certificates from assemblies.

The output after the banner depends on the assembly. An ordinary framework assembly may have no usable certificate. On this machine, running secutil -x against mscorlib.dll produced a certificate-decoding error even though the process status was 0. Therefore, inspect both the diagnostic output and the extracted content; do not use the exit status alone as proof that a certificate was found.

Certificate inspection can expose security-relevant identity data. Keep captured output in an access-controlled location if the assembly or its metadata is sensitive. Do not run SecUtil as root merely to read a file. Fix the file permissions or copy the input through an approved process instead.

5. Diagnose the common failures

If the path is wrong, check it without changing anything:

$ ls -l /path/to/assembly.dll
$ test -r /path/to/assembly.dll && echo readable

If SecUtil reports a missing file, malformed assembly or certificate-decoding exception, stop and verify the file type and provenance. Do not rename an arbitrary file to .dll and retry. For a signed assembly, obtain a known-good copy from the publisher, then compare it with the copy you inspected using your normal package or release verification process.

If you accidentally put a formatting option where SecUtil expects the assembly, it can try to open that option as a file. Keep the ordering shown above: formatting mode, operation, then filename. Use secutil -h or secutil -help to display the installed help without inspecting an assembly.

Done means

  • You confirmed the installed executable and Mono version.
  • You inspected the intended assembly with -s and recorded its name, version and public key.
  • You selected -v, -c or -a before the operation when reusable formatting mattered.
  • You treated certificate output and diagnostic text as data to verify, not as proof of trust.
  • You kept the original assembly untouched and did not use elevated privileges without a separate, justified access requirement.