Skip to content
Registry StackDocsDevelopment (unreleased)

evidencectl jwk from-pem command reference

View as Markdown

Convert one PEM public key into a public JWK whose kid is its RFC 7638 thumbprint.

This page is generated from the public Clap command tree for Registry Stack source version 0.40.0 and catalog SHA-256 42b4f89103fb6b0fc57282f99a8d8ab8fc777b3c745d6243720ff4a99ba1f57f. Hidden implementation commands are omitted.

Convert one PEM public key into a public JWK whose kid is its RFC 7638 thumbprint. Accepts a PUBLIC KEY (SubjectPublicKeyInfo) or RSA PUBLIC KEY (PKCS #1) block: EC P-256 becomes ES256, EC P-384 becomes ES384, and RSA takes the algorithm named by --alg. A private key is refused.

evidencectl jwk from-pem [OPTIONS] <PEM>
ConditionRequirement
Command invocation--output <OUTPUT> and --output-dir <OUTPUT_DIR> cannot be used together.
ArgumentAlways requiredDefaultValuesEnvironmentDescription
<PEM>Yesn/an/an/aPEM public key file, or - to read standard input
OptionAlways requiredDefaultValuesEnvironmentDescription
--alg <ALG>Non/aes256, es384, rs256, rs384n/aJWS algorithm the key is published for; required for RSA keys
--output <OUTPUT>Non/an/an/aWrite the JWK to this file instead of standard output
--output-dir <OUTPUT_DIR>Non/an/an/aWrite the JWK into this existing directory as <kid>.jwk.json
--forceNon/an/an/aOverwrite an existing output file
--format <output_format>Nohumanhuman, json, junitn/aSelect human-readable or machine-readable output. junit is accepted only by fixture runs (test and fixtures run)
-h, --helpNon/an/an/aPrint help (see a summary with ‘-h’)

Run npm run generate from docs/site after changing a public command, argument, option, default, environment binding, or help description.