OnCallReady

Commands

openssl - OpenSSL command line program

openssl command [ options ... ]

Options you will use

s_client -connect H:P
TLS handshake; prints the chain the server sent and the verify result
-servername N
SNI. Sent automatically from -connect when it is a hostname; needed when you connect by IP
-showcerts
every certificate the server sent, as PEM
-CAfile F
trust these CAs instead of the system store
-verify_hostname N
s_client does NOT check the name unless you ask
x509 -in F -noout -text
decode a certificate
x509 -noout -subject -issuer -dates
the fields that matter
x509 -noout -ext subjectAltName
the names it is valid for
x509 -checkend N
exit 1 if it expires within N seconds
verify -CAfile root -untrusted int leaf
build and check a chain offline
crl2pkcs7 -nocrl -certfile F | pkcs7 -print_certs -noout
list every certificate in a bundle (x509 reads only the first)
pkey -in K -pubout
public half of a key: compare with x509 -pubkey
genrsa -out K 2048
an RSA private key (PKCS#8 PEM, file mode 600)
req -new -key K -out R.csr -subj "/CN=jane/O=dev"
a certificate signing request. -subj must start with /; each O= becomes a Kubernetes group
req -new -newkey rsa:2048 -nodes -keyout K -out R.csr -subj S
key and request in one go (-nodes: no passphrase)
req -in R.csr -noout -text | -subject
read a request back
req -x509 -new -key K -subj /CN=my-ca -days 365 -out ca.crt
a self-signed (CA) certificate
x509 -req -in R.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out C.crt -days N
sign a request with a CA (the manual way on a control plane node)
-checkend SECONDS
An openssl x509 option: exit 1 if the certificate expires within SECONDS, 0 if not.

Examples

$ openssl s_client -connect api.lab:443 -servername api.lab </dev/null

the chain and the verdict

$ openssl genrsa -out jane.key 2048 && openssl req -new -key jane.key -out jane.csr -subj "/CN=jane/O=dev"

the first two steps of a Kubernetes user

$ echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -noout -dates

expiry from the wire

$ openssl verify -CAfile root.pem -untrusted int.pem leaf.pem

is this chain complete

Gotchas

Taught in

Try openssl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.