Спойлер
Usage: pkcs11-tool [OPTIONS]
Options:
--module <arg> Specify the module to load (mandatory)
--show-info, -I Show global token information
--list-slots, -L List available slots
--list-token-slots, -T List slots with tokens
--list-mechanisms, -M List mechanisms supported by the token
--list-objects, -O Show objects on token
--sign, -s Sign some data
--hash, -h Hash some data
--mechanism, -m <arg> Specify mechanism (use -M for a list of supported mechanisms)
--login, -l Log into the token first
--login-type <arg> Specify login type ('so', 'user', 'context-specific'; default:'user')
--pin, -p <arg> Supply User PIN on the command line (if used in scripts: careful!)
--puk <arg> Supply User PUK on the command line
--new-pin <arg> Supply new User PIN on the command line
--so-pin <arg> Supply SO PIN on the command line (if used in scripts: careful!)
--init-token Initialize the token, its label and its SO PIN (use with --label and --so-pin)
--init-pin Initialize the User PIN (use with --pin and --login)
--change-pin, -c Change User PIN
--unlock-pin Unlock User PIN (without '--login' unlock in logged in session; otherwise '--login-type' has to be 'context-specific')
--keypairgen, -k Key pair generation
--key-type <arg> Specify the type and length of the key to create, for example rsa:1024 or EC:prime256v1
--write-object, -w <arg> Write an object (key, cert, data) to the card
--read-object, -r Get object's CKA_VALUE attribute (use with --type)
--delete-object, -b Delete an object
--application-label <arg> Specify the application label of the data object (use with --type data)
--application-id <arg> Specify the application ID of the data object (use with --type data)
--type, -y <arg> Specify the type of object (e.g. cert, privkey, pubkey, data)
--id, -d <arg> Specify the ID of the object
--label, -a <arg> Specify the label of the object
--slot <arg> Specify the ID of the slot to use
--slot-description <arg> Specify the description of the slot to use
--slot-index <arg> Specify the index of the slot to use
--token-label <arg> Specify the token label of the slot to use
--set-id, -e <arg> Set the CKA_ID of an object, <args>= the (new) CKA_ID
--attr-from <arg> Use <arg> to create some attributes when writing an object
--input-file, -i <arg> Specify the input file
--output-file, -o <arg> Specify the output file
--test, -t Test (best used with the --login or --pin option)
--test-hotplug Test hotplug capabilities (C_GetSlotList + C_WaitForSlotEvent)
--moz-cert, -z <arg> Test Mozilla-like keypair gen and cert req, <arg>=certfile
--verbose, -v Verbose operation. (Set OPENSC_DEBUG to enable OpenSC specific debugging)
--private Set the CKA_PRIVATE attribute (object is only viewable after a login)
--test-ec Test EC (best used with the --login or --pin option)
Второй модуль тоже самое выдает.