如何通过certutil由cert9.db生成cert7.db?适配遗留LDAP项目
Great question! The cert7.db format is the legacy DBM-based NSS certificate store, while cert9.db uses the newer SQLite-backed format. Since you’re working with a legacy LDAP service that requires the older format, here’s how you can convert or recreate a cert7.db from your existing cert9.db on Debian:
Step 1: Prepare a Legacy Database Directory
First, create a new directory to hold your cert7.db (and associated key3.db/secmod.db files):
mkdir -p ./legacy_cert_db
Step 2: Initialize the Legacy DBM Database
Use certutil with the -dbtype dbm flag to initialize a cert7-style database. You’ll need a password file (or you can omit -f and enter the password interactively):
# Create a password file (replace "your_db_password" with your actual password) echo "your_db_password" > ./db_password.txt # Initialize the legacy database certutil -N -d ./legacy_cert_db -f ./db_password.txt -dbtype dbm
Note: The -dbtype dbm flag forces certutil to use the old cert7 format instead of the default SQLite cert9.
Step 3: Export Certificates from cert9.db
Next, export all certificates from your existing cert9.db directory. Replace ./modern_cert_db with the path to your cert9 database folder:
# List all certificate nicknames to identify what to export certutil -L -d ./modern_cert_db # Export each certificate individually (repeat for all needed certs) certutil -L -d ./modern_cert_db -n "Your Cert Nickname" -a > ./exported_cert.pem
If you have multiple certificates, you can automate this with a simple loop (adjust the nickname pattern as needed):
for nickname in $(certutil -L -d ./modern_cert_db | awk '{print $1}' | grep -v "Certificate"); do certutil -L -d ./modern_cert_db -n "$nickname" -a > "./${nickname}.pem" done
Step 4: Import Certificates into cert7.db
Now import each exported PEM file into your new legacy database. Use the -t flag to set trust attributes (adjust CT,C,C to match your LDAP service’s requirements—this example sets client, server, and email trust):
# Import a single certificate certutil -A -d ./legacy_cert_db -f ./db_password.txt -n "Your Cert Nickname" -t "CT,C,C" -i ./exported_cert.pem -dbtype dbm # Bulk import (if you used the loop above) for pem_file in ./*.pem; do nickname=$(basename "$pem_file" .pem) certutil -A -d ./legacy_cert_db -f ./db_password.txt -n "$nickname" -t "CT,C,C" -i "$pem_file" -dbtype dbm done
Step 5: Verify the Legacy Database
Confirm that your cert7.db, key3.db, and secmod.db were created correctly and contain the certificates:
certutil -L -d ./legacy_cert_db -dbtype dbm
Alternative: Use Older NSS Tools (If Needed)
If your current certutil version has issues with the -dbtype dbm flag, you can install an older version of the NSS tools that natively supports cert7. On Debian, you can check for older packages using:
apt-cache show libnss3-tools | grep Version
Install an older version (e.g., from a previous Debian release) using apt-get install libnss3-tools=<version>, then repeat the steps above without needing the -dbtype flag.
内容的提问来源于stack exchange,提问作者Giuseppe Terrasi

