---
title: "OpenSSL Certificates Cheatsheet | FindUtils"
description: "Inspect PEM certs, CSRs, and keys, convert formats, verify chains, and probe live TLS"
url: https://findutils.com/cheatsheets/openssl-certificates/
---

# OpenSSL Certificates Cheatsheet

Inspect PEM certs, CSRs, and keys, convert formats, verify chains, and probe live TLS 31 commands in 7 sections, filed under [Linux & Terminal](https://findutils.com/cheatsheets/linux/).

## Inspect PEM

- `openssl x509 -in cert.pem -text -noout`: Print a certificate
- `openssl x509 -in cert.pem -noout -subject -issuer -dates`: Subject, issuer, and dates
- `openssl x509 -in cert.pem -noout -ext subjectAltName`: Print SAN
- `openssl x509 -in cert.pem -noout -fingerprint -sha256`: SHA-256 fingerprint
- `openssl req -in csr.pem -text -noout`: Print a CSR
- `openssl crl -in crl.pem -text -noout`: Print a CRL

## Keys

- `openssl pkey -in key.pem -text -noout`: Inspect a private key (prints material)
- `openssl pkey -in key.pem -pubout`: Write the public key
- `openssl pkey -in key.pem -check`: Check key consistency
- `openssl genpkey -algorithm RSA -out key.pem -pkeyopt rsa_keygen_bits:2048`: Generate an RSA key
- `openssl genpkey -algorithm ED25519 -out key.pem`: Generate an Ed25519 key
- `openssl rsa -in key.pem -pubout`: RSA public key from an RSA key file

## Create certs

- `openssl req -new -key key.pem -out req.csr`: Create a CSR
- `openssl req -new -x509 -key key.pem -out cert.pem -days 365`: Self-signed certificate
- `openssl x509 -req -in req.csr -signkey key.pem -out cert.pem -days 90`: Sign a CSR with a key
- `openssl req -new -x509 -nodes -newkey rsa:2048 -keyout key.pem -out cert.pem -days 30 -subj "/CN=localhost"`: One-shot local cert and key

## Convert

- `openssl x509 -in cert.der -inform DER -out cert.pem`: DER cert to PEM
- `openssl x509 -in cert.pem -outform DER -out cert.der`: PEM cert to DER
- `openssl pkcs12 -in bundle.p12 -nodes -out bundle.pem`: PKCS#12 to PEM
- `openssl pkcs12 -export -in cert.pem -inkey key.pem -out bundle.p12`: PEM cert and key to PKCS#12
- `openssl x509 -in cert.pem -noout -pubkey`: Extract the cert public key

## Verify

- `openssl verify -CAfile ca.pem cert.pem`: Verify a cert against a CA file
- `openssl verify -untrusted chain.pem -CAfile root.pem leaf.pem`: Verify with intermediates
- `openssl x509 -in cert.pem -noout -checkend 86400`: Fail if cert ends within 1 day
- `openssl ocsp -issuer ca.pem -cert cert.pem -url http://ocsp.example/`: Query OCSP for a cert
- `diff <(openssl x509 -in a.pem -noout -modulus) <(openssl pkey -in key.pem -noout -modulus)`: Check cert and key modulus match

## Live TLS

- `openssl s_client -connect host:443 -servername host`: Open a TLS session
- `openssl s_client -connect host:443 -servername host </dev/null | openssl x509 -noout -text`: Show the presented cert
- `openssl s_client -connect host:443 -showcerts`: Print the cert chain
- `echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -noout -dates`: Print live notBefore/notAfter

## Sources

- `https://docs.openssl.org/3.6/man1/openssl/`: OpenSSL 3.6 command index: certificate, key, verification, and TLS commands.

## Related

- Cheatsheet: [Linux Commands](https://findutils.com/cheatsheets/linux-commands/)
- Cheatsheet: [Bash Scripting](https://findutils.com/cheatsheets/bash-scripting/)
- Cheatsheet: [Vim Editor](https://findutils.com/cheatsheets/vim-editor/)
- Guide: [PEM Decoder: Read Certificates and CSRs Locally](https://findutils.com/guides/pem-decoder-guide/)
- Tool: [PEM Decoder](https://findutils.com/developers/pem-decoder/)
