trust
Manage system trust policy certificate store
TLDR
List trust policy store items
SYNOPSIS
trust command [options]
DESCRIPTION
trust manages the shared system trust policy store, which contains trusted CA certificates, blocklisted certificates, and trust policies. It allows administrators to add, remove, and extract trust anchors used for TLS/SSL verification across the system.
Changes made with trust affect all applications that use the p11-kit trust module, providing a unified way to manage certificates rather than configuring each application individually.
PARAMETERS
list
List trust policy store itemsanchor file
Add a trust anchor to the storeanchor --remove file
Remove a trust anchorextract --format=format path
Extract trust anchors in specified format--filter=type
Filter by type (ca-anchors, blocklist, certificates, trust-policy)--format=format
Output format (x509-file, x509-directory, pem-file, etc.)--purpose=purpose
Filter by purpose (server-auth, client-auth, email, code-signing)
CAVEATS
Requires root privileges to modify system trust store. Changes may require applications to be restarted to take effect. The store format and location varies by distribution.
HISTORY
Part of p11-kit, developed as part of the FreeDesktop.org project to provide a standard way to manage trust anchors across Linux distributions. Replaces distribution-specific methods like update-ca-certificates.
SEE ALSO
update-ca-trust(8), openssl(1), p11-kit(8)
