pkg.soopen package index

brew / rang 4030

Installer pkcs11-tools avec Homebrew

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de pkcs11-tools pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install pkcs11-tools

local Homebrew formula metadata

aperçu

Résumé du paquet

Tools to manage objects on PKCS#11 crypotographic tokens

Commandes et alias

  • masqreq
  • p11cat
  • p11cp
  • p11importcert
  • p11importdata
  • p11importpubk
  • p11init
  • p11kcv
  • p11keycomp
  • p11keygen
  • p11ls
  • p11mkcert
  • p11more
  • p11mv
  • p11od
  • p11req
  • p11rewrap
  • p11rm
  • p11setattr
  • p11slotinfo
  • p11unwrap
  • p11wrap
  • with_aws
  • with_beid
  • with_kryoptic
  • with_luna
  • with_nfast
  • with_nss
  • with_pkcs11_common
  • with_softhsm
  • with_utimaco
  • with_yubico

historique

Historique du projet et usages

PKCS#11 tools is a suite of small command-line programs for managing cryptographic keys, certificates, and other objects across interoperable hardware and software tokens.

Historique du projet

pkcs11-tools was created to provide unified, interoperable key-management primitives for cryptographic tokens implementing PKCS#11. The official manual cites underspecified object conventions, differences between Java implementations, cumbersome JVM setup, and proprietary vendor tools as motivations.

The toolkit evolved through releases adding templates and broader attribute handling, CKA_ALLOWED_MECHANISMS support, JWK output, reworked vendor wrappers, OpenSSL 3 migration, and support for the ML-KEM, ML-DSA, and SLH-DSA post-quantum algorithms.

Historique d'adoption

The toolkit targets a range of hardware and software PKCS#11 implementations rather than a single vendor. Official documentation covers major HSM brands and software tokens including SoftHSM, NSS, and Kryoptic, as well as interoperability with IBM and Oracle Java environments.

It is available through Homebrew, while the source documentation also covers Linux, macOS, AIX, Solaris, and cross-compiled Windows builds.

Modes d'utilisation

Users select a PKCS#11 library and token by command options or environment variables, then use focused p11 commands to list, inspect, generate, import, move, remove, wrap, or unwrap objects and to create CSRs or certificates.

Vendor-oriented with_* wrappers can auto-detect libraries and read .pkcs11rc or .pkcs11rc.<vendor> files. The search begins in the current directory and proceeds upward to $HOME. These shell-sourced files may contain PKCS11PASSWORD, so they can also act as credential-bearing files and require appropriate permissions.

Pourquoi les passionnés de paquets s'y intéressent

The project supplies Unix-like commands such as p11ls, p11mv, p11rm, p11od, and p11more for a security API whose vendor tooling is often proprietary and inconsistent. That composable command vocabulary makes heterogeneous HSM and token administration more approachable.

Its breadth extends beyond object inspection to key generation, wrapping, certificate import, CSR creation, token initialization, vendor wrapper scripts, shell completion, and post-quantum PKCS#11 algorithms.

Chronologie

  • July 2021: Version 2.4 added template support to numerous key-management commands.
  • October 2021: Version 2.5 added CKA_ALLOWED_MECHANISMS support and advanced the wrapped-key grammar.
  • June 2023: Version 2.6 added JWK output to key-generation and wrapping commands.
  • Later development: The toolkit moved to OpenSSL 3 and added PKCS#11 v3.2 post-quantum algorithms.

Related projects

  • PKCS#11 is the standard interface around which the toolkit is built.
  • SoftHSM, NSS, and Kryoptic are supported software-token implementations.
  • libpkcs11shim can be installed separately to trace PKCS#11 calls through the wrapper scripts.

Sources

  • Official installation guide: https://github.com/Mastercard/pkcs11-tools/blob/master/docs/INSTALL.md
  • Official manual: https://github.com/Mastercard/pkcs11-tools/blob/master/docs/MANUAL.md
  • Official repository: https://github.com/Mastercard/pkcs11-tools

posture de sécurité

Niveau de risque : vert

narrow executable package without higher-risk signals.

Classificateur de risque

risque vert · confiance faible · appliance

Pourquoi

  • narrow executable package without higher-risk signals

Signaux

  • metadata:no-higher-risk-signals

Comportement d'installation

  • Aucun hook post-install Homebrew n’est enregistré dans les métadonnées de formule.
  • Les métadonnées de bottle Homebrew sont disponibles pour 6 plateformes.
  • S’installe avec 1 dépendances d’exécution.
  • Les métadonnées de compilation listent 1 dépendances de compilation.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./.pkcs11rc./.pkcs11rc.<vendor>~/.pkcs11rc~/.pkcs11rc.<vendor>

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
./.pkcs11rc./.pkcs11rc.<vendor>~/.pkcs11rc~/.pkcs11rc.<vendor>

exécutables

Exécutables installés

CommandeTypeExpositionNote
masqreqcliexécutable global
p11catcliexécutable global
p11cpcliexécutable global
p11importcertcliexécutable global
p11importdatacliexécutable global
p11importpubkcliexécutable global
p11initcliexécutable global
p11kcvcliexécutable global
p11keycompcliexécutable global
p11keygencliexécutable global
p11lscliexécutable global
p11mkcertcliexécutable global
p11morecliexécutable global
p11mvcliexécutable global
p11odcliexécutable global
p11reqcliexécutable global
p11rewrapcliexécutable global
p11rmcliexécutable global
p11setattrcliexécutable global
p11slotinfocliexécutable global
p11unwrapcliexécutable global
p11wrapcliexécutable global
with_awscliexécutable global
with_beidcliexécutable global
with_kryopticcliexécutable global
with_lunacliexécutable global
with_nfastcliexécutable global
with_nsscliexécutable global
with_pkcs11_commoncliexécutable global
with_softhsmcliexécutable global
with_utimacocliexécutable global
with_yubicocliexécutable global

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-09-19
version du gestionnaire3.1.0
gestionnaire mis à jour2026-09-11
données localesOK
amontnot checked
dernière version détectéenon détecté

https://github.com/Mastercard/pkcs11-tools

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:pkcs11-tools
Version3.1.0
Gestionnaire de paquetsHomebrew
Page du gestionnaire de paquetshttps://formulae.brew.sh/formula/pkcs11-tools
Page d'accueilhttps://github.com/Mastercard/pkcs11-tools
Dépôthttps://github.com/Mastercard/pkcs11-tools
LicenceApache-2.0
Archive sourcehttps://github.com/Mastercard/pkcs11-tools/releases/download/v3.1.0/pkcs11-tools-3.1.0.tar.gz
Dernière mise à jour2026-09-11T13:06:39Z
Pulseupdated
Dépendancesopenssl@3
Dépendances de compilationpkgconf
Bouteilledisponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
post-install Homebrewnon défini
Serviceaucun déclaré

faits du registre

Détails de la base source

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namepkcs11-tools
Version Scheme0
Revision0
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • stable

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation