OpenSSL and certificates
Inspecting remote and local certificates, expiry dates, keys and CSRs, format conversion.
Remote certificates
Certificate expiry date of a site
echo | openssl s_client -connect <domain>:443 -servername <domain> 2>/dev/null | openssl x509 -noout -dates
Who issued the certificate and for which names
echo | openssl s_client -connect <domain>:443 -servername <domain> 2>/dev/null | openssl x509 -noout -subject -issuer -ext subjectAltName
Show the full certificate chainadvanced
openssl s_client -connect <domain>:443 -servername <domain> -showcerts
Check a specific TLS versionadvanced
openssl s_client -connect <domain>:443 -tls1_3
Local files
Read a certificate
openssl x509 -in <cert> -noout -text
Expiry date of a certificate file
openssl x509 -in <cert> -noout -enddate
Will it expire within 30 days?advanced
openssl x509 -in <cert> -noout -checkend 2592000
Does a key match a certificate?advanced
openssl x509 -in <cert> -noout -pubkey | openssl sha256 && openssl pkey -in <key_file> -pubout | openssl sha256
The two hashes must be identical.
Creating keys and certificates
Self-signed certificate for local dev
openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=localhost"Private key and CSR for a CA
openssl req -new -newkey rsa:2048 -nodes -keyout <domain>.key -out <domain>.csr -subj "/CN=<domain>"
Read a CSR
openssl req -in <domain>.csr -noout -text
Conversion and utilities
PEM to PKCS#12 (.pfx)advanced
openssl pkcs12 -export -out bundle.pfx -inkey <key_file> -in <cert>
PKCS#12 to PEMadvanced
openssl pkcs12 -in bundle.pfx -out bundle.pem -nodesRandom password / secret
openssl rand -base64 32SHA-256 of a file
openssl sha256 <file>
Base64 encode and decode
echo -n 'text' | openssl base64 && echo 'dGV4dA==' | openssl base64 -d