Provided by: libreswan_5.2-2.2ubuntu1_amd64 

NAME
ipsec-checknss - Check or initialize the IPsec NSS database
SYNOPSIS
ipsec checknss [--nssdir /var/lib/ipsec/nss] [--settrusts]
DESCRIPTION
Checknss checks or initialises the NSS database where all private keys for RSA and certificate keypairs
are stored. To remove an existing IPsec NSS database, remove all the *.db files and pkcs11.txt from the
NSS data directory (default: /var/lib/ipsec/nss). If database exists returns successfully.
SEE ALSO
ipsec.conf(5), ipsec(8), ipsec-add(8), ipsec-algparse(8), ipsec-briefconnectionstatus(8), ipsec-
briefstatus(8), ipsec-certutil(8), ipsec-checkconfig(8), ipsec-checknflog(8), ipsec-connectionstatus(8),
ipsec-crlutil(8), ipsec-delete(8), ipsec-down(8), ipsec-ecdsasigkey(8), ipsec-fetchcrls(8), ipsec-
fipsstatus(8), ipsec-globalstatus(8), ipsec-import(8), ipsec-initnss(8), ipsec-letsencrypt(8), ipsec-
listall(8), ipsec-listcacerts(8), ipsec-listcerts(8), ipsec-listcrls(8), ipsec-listen(8), ipsec-
listpubkeys(8), ipsec-modutil(8), ipsec-newhostkey(8), ipsec-ondemand(8), ipsec-pk12util(8), ipsec-
pluto(8), ipsec-purgeocsp(8), ipsec-redirect(8), ipsec-replace(8), ipsec-rereadall(8), ipsec-
rereadcerts(8), ipsec-rereadsecrets(8), ipsec-restart(8), ipsec-route(8), ipsec-rsasigkey(8), ipsec-
setup(8), ipsec-showhostkey(8), ipsec-showroute(8), ipsec-showstates(8), ipsec-shuntstatus(8), ipsec-
start(8), ipsec-status(8), ipsec-stop(8), ipsec-trafficstatus(8), ipsec-unroute(8), ipsec-up(8), ipsec-
vfychain(8), ipsec-whack(8)
BUGS
none
AUTHOR
Tuomo Soini
Libreswan 5.2 07/30/2025 IPSEC-CHECKNSS(8)