pkcs11_inspect uses the same configuration file and arguments than pam_pkcs11(8) PAM module. It loads defined mapper modules, and use them to look into the certificate for required entries (ie: ms_mapper looks for ms UPN entries, and so on).
When a mapper module finds a proper entry in the certificate, it converts to UTF-8 and print it to stdout.
As it uses the same configuration file as pam_pkcs11, all pam_pkcs11 options are also available. Note that some of them have no sense in a non-PAM environment, so they will be ignored. Some mapper options (mapfile, ignorecase) have no effect on certificate contents, so they will be ignored too.
/etc/pam_pkcs11/pam_pkcs11.conf
pkcs11_inspect
Alternatively you can specify options:
pkcs11_inspect debug config_file=${HOME}/.pam_pkcs11.conf
Juan Antonio Martinez <jonsito@teleline.es>