.\" Automatically generated by Pod::Man 4.07 (Pod::Simple 3.32) .\" .\" Standard preamble: .\" ======================================================================== .de Sp \" Vertical space (when we can't use .PP) .if t .sp .5v .if n .sp .. .de Vb \" Begin verbatim text .ft CW .nf .ne \\$1 .. .de Ve \" End verbatim text .ft R .fi .. .\" Set up some character translations and predefined strings. \*(-- will .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left .\" double quote, and \*(R" will give a right double quote. \*(C+ will .\" give a nicer C++. Capital omega is used to do unbreakable dashes and .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, .\" nothing in troff, for use with C<>. .tr \(*W- .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' .ie n \{\ . ds -- \(*W- . ds PI pi . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch . ds L" "" . ds R" "" . ds C` "" . ds C' "" 'br\} .el\{\ . ds -- \|\(em\| . ds PI \(*p . ds L" `` . ds R" '' . ds C` . ds C' 'br\} .\" .\" Escape single quotes in literal strings from groff's Unicode transform. .ie \n(.g .ds Aq \(aq .el .ds Aq ' .\" .\" If the F register is >0, we'll generate index entries on stderr for .\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index .\" entries marked with X<> in POD. Of course, you'll have to process the .\" output yourself in some meaningful fashion. .\" .\" Avoid warning from groff about undefined register 'F'. .de IX .. .if !\nF .nr F 0 .if \nF>0 \{\ . de IX . tm Index:\\$1\t\\n%\t"\\$2" .. . if !\nF==2 \{\ . nr % 0 . nr F 2 . \} .\} .\" .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). .\" Fear. Run. Save yourself. No user-serviceable parts. . \" fudge factors for nroff and troff .if n \{\ . ds #H 0 . ds #V .8m . ds #F .3m . ds #[ \f1 . ds #] \fP .\} .if t \{\ . ds #H ((1u-(\\\\n(.fu%2u))*.13m) . ds #V .6m . ds #F 0 . ds #[ \& . ds #] \& .\} . \" simple accents for nroff and troff .if n \{\ . ds ' \& . ds ` \& . ds ^ \& . ds , \& . ds ~ ~ . ds / .\} .if t \{\ . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' .\} . \" troff and (daisy-wheel) nroff accents .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' .ds 8 \h'\*(#H'\(*b\h'-\*(#H' .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] .ds ae a\h'-(\w'a'u*4/10)'e .ds Ae A\h'-(\w'A'u*4/10)'E . \" corrections for vroff .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' . \" for low resolution devices (crt and lpr) .if \n(.H>23 .if \n(.V>19 \ \{\ . ds : e . ds 8 ss . ds o a . ds d- d\h'-1'\(ga . ds D- D\h'-1'\(hy . ds th \o'bp' . ds Th \o'LP' . ds ae ae . ds Ae AE .\} .rm #[ #] #H #V #F C .\" ======================================================================== .\" .IX Title "xsec-cipher.pod 1" .TH xsec-cipher.pod 1 "2018-08-03" "1.7.3" "Apache XML Security" .\" For nroff, turn off justification. Always turn off hyphenation; it makes .\" way too many mistakes in technical documents. .if n .ad l .nh .SH "NAME" xmlsec\-cipher \- Perform basic encryption and decryption of XML documents .SH "SYNOPSIS" .IX Header "SYNOPSIS" \&\fBxmlsec-cipher\fR [\fB\-i\fR] ([\fB\-d\fR] | \fB\-de\fR | \fB\-ef\fR | \fB\-ex\fR) [\fB\-x\fR] [\fB\-o\fR \fIoutput\fR] \fB\-k\fR [kek] (\fIfilename\fR [\fIpassword\fR] | \fIkey-string\fR) \fIinput\fR .SH "DESCRIPTION" .IX Header "DESCRIPTION" \&\fBxmlsec-cipher\fR encrypts or decrypts an \s-1XML\s0 document following the \s-1XML\s0 Digital Signature and Encryption specifications using the Apache \s-1XML\s0 Security for \*(C+ library. The default action is to decrypt the input file. Other operations can be selected with the \fB\-de\fR, \fB\-ef\fR, or \fB\-ex\fR options. The result of the operation, whether encryption or decryption, will be printed to standard output. .SH "OPTIONS" .IX Header "OPTIONS" Note that each option must be given as a separate argument. .IP "\fB\-\-decrypt\fR, \fB\-d\fR" 4 .IX Item "--decrypt, -d" Reads in the input file as an \s-1XML\s0 file, searches for an EncryptedData node, and decrypts the output, printing it to standard output. This is the default operation and does not need to be specified. .IP "\fB\-\-decrypt\-element\fR, \fB\-de\fR" 4 .IX Item "--decrypt-element, -de" Reads in the input file as an \s-1XML\s0 file and prints it out with the fist encrypted element decrypted. .IP "\fB\-\-encrypt\-file\fR, \fB\-ef\fR" 4 .IX Item "--encrypt-file, -ef" Reads the input file as raw data and creates an \s-1XML\s0 EncryptedData document as output, containing the encrypted version of that input data. .IP "\fB\-\-encrypt\-xml\fR, \fB\-ex\fR" 4 .IX Item "--encrypt-xml, -ex" Parse the input file as \s-1XML,\s0 find the document element, and encrypt the document, outputting the result as an \s-1XML\s0 EncryptedData document. .IP "(\fB\-\-key\fR | \fB\-k\fR) [kek] \fItype\fR \fIfilename\fR [\fIpassword\fR]" 4 .IX Item "(--key | -k) [kek] type filename [password]" .PD 0 .IP "(\fB\-\-key\fR | \fB\-k\fR) [kek] \fItype\fR \fIkey-string\fR" 4 .IX Item "(--key | -k) [kek] type key-string" .PD Specifies the key to use for encryption or decryption. .Sp If the first argument following the \fB\-\-key\fR or \fB\-k\fR option is the string \&\f(CW\*(C`kek\*(C'\fR, the following key argument will be used as a Key EncryptionKey. .Sp \&\fItype\fR specifies the key type and must be one of X509, \s-1RSA, AES128, AES192, AES256, AES128\-GCM, AES192\-GCM, AES256\-GCM,\s0 or 3DES. .Sp The remaining arguments depend on the key type. For X509, only a \&\fIfilename\fR may be given and must contain an \s-1RSA KEK\s0 certificate. For \&\s-1RSA,\s0 a \fIfilename\fR and \fIpassword\fR may specify an \s-1RSA\s0 private key file and its password (this must be a \s-1KEK\s0). For the other key types, the last argument is the string to use as the key. .IP "\fB\-\-xkms\fR, \fB\-x\fR" 4 .IX Item "--xkms, -x" The key specified after this argument on the command line is interpreted as an \s-1XKMS\s0 RSAKeyPair encryption key. .IP "\fB\-\-interop\fR, \fB\-i\fR" 4 .IX Item "--interop, -i" Use hte interop resolver for Baltimore interop examples. .IP "\fB\-\-out\-file\fR \fIfile\fR, \fB\-o\fR \fIfile\fR" 4 .IX Item "--out-file file, -o file" Rather than printing the result to standard output, write it to the specified file. .SH "RETURN STATUS" .IX Header "RETURN STATUS" \&\fBxmlsec-cipher\fR exits with status 0 if the encryption or decryption operation was successful and with status 1 if it failed. If it cannot process the input file for some reason, it exits with status 2. .SH "AUTHOR" .IX Header "AUTHOR" This manual page was written by Russ Allbery for Debian. .SH "MANUAL LICENSE" .IX Header "MANUAL LICENSE" The authors hereby relinquish any claim to any copyright that they may have in this work, whether granted under contract or by operation of law or international treaty, and hereby commit to the public, at large, that they shall not, at any time in the future, seek to enforce any copyright in this work against any person or entity, or prevent any person or entity from copying, publishing, distributing or creating derivative works of this work.