openssl - OpenSSL command line program
openssl command [ options ... ]
Options you will use
s_client -connect H:P- TLS handshake; prints the chain the server sent and the verify result
-servername N- SNI. Sent automatically from -connect when it is a hostname; needed when you connect by IP
-showcerts- every certificate the server sent, as PEM
-CAfile F- trust these CAs instead of the system store
-verify_hostname N- s_client does NOT check the name unless you ask
x509 -in F -noout -text- decode a certificate
x509 -noout -subject -issuer -dates- the fields that matter
x509 -noout -ext subjectAltName- the names it is valid for
x509 -checkend N- exit 1 if it expires within N seconds
verify -CAfile root -untrusted int leaf- build and check a chain offline
crl2pkcs7 -nocrl -certfile F | pkcs7 -print_certs -noout- list every certificate in a bundle (x509 reads only the first)
pkey -in K -pubout- public half of a key: compare with x509 -pubkey
genrsa -out K 2048- an RSA private key (PKCS#8 PEM, file mode 600)
req -new -key K -out R.csr -subj "/CN=jane/O=dev"- a certificate signing request. -subj must start with /; each O= becomes a Kubernetes group
req -new -newkey rsa:2048 -nodes -keyout K -out R.csr -subj S- key and request in one go (-nodes: no passphrase)
req -in R.csr -noout -text | -subject- read a request back
req -x509 -new -key K -subj /CN=my-ca -days 365 -out ca.crt- a self-signed (CA) certificate
x509 -req -in R.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out C.crt -days N- sign a request with a CA (the manual way on a control plane node)
-checkend SECONDS- An
openssl x509option: exit 1 if the certificate expires within SECONDS, 0 if not.
Examples
$ openssl s_client -connect api.lab:443 -servername api.lab </dev/nullthe chain and the verdict
$ openssl genrsa -out jane.key 2048 && openssl req -new -key jane.key -out jane.csr -subj "/CN=jane/O=dev"the first two steps of a Kubernetes user
$ echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -noout -datesexpiry from the wire
$ openssl verify -CAfile root.pem -untrusted int.pem leaf.pemis this chain complete
Gotchas
- s_client prints the depth= and verify lines on stderr and the chain on stdout. It exits 0 even when verification fails - read "Verify return code".
- Verify return code 20/21 = missing intermediate (or unknown CA); 10 = expired; 18/19 = self-signed; 62 = hostname mismatch.
Taught in
Try openssl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.