↑ ↓ select, Enter open, Esc close

SSL and certificates

Check certificates, read expiry dates, test chains and renew Let's Encrypt. HTTPS is mandatory, for rankings too.

17 one-liners: 13 harmless, 4 caution, 0 destructive

All SSL and certificates one-liners

Check the contents of a CSR before submitting it

$openssl req -in example.com.csr -noout -text -verify
harmless

Check the SSL certificate expiration date of a website

$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates
harmless

Check whether a certificate expires within the next days

#openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -checkend $(( 30 * 86400 )) && echo "noch gültig" || echo "läuft bald ab"
harmless

Check whether a private key matches a certificate

#openssl x509 -noout -modulus -in /etc/ssl/certs/example.com.crt | openssl md5 && openssl rsa -noout -modulus -in /etc/ssl/private/example.com.key | openssl md5
harmless

Check whether a server supports TLS 1.3

$openssl s_client -connect example.com:443 -servername example.com -tls1_3 </dev/null 2>/dev/null | grep -E "^New,|Protocol *:"
harmless

Check whether a website sends the HSTS header

$curl -sI https://example.com/ | grep -i "^strict-transport-security"
harmless

Server is clean. Is the site?

How fast does the website really load?

GENLOC.SEO measures PageSpeed and Core Web Vitals on mobile and desktop and tells you clearly what to fix first. Free, no time limit.

by GENLOC.NETWORK, the team behind myline.de

Check whether a website's certificate is trusted

$openssl s_client -connect example.com:443 -servername example.com -verify_hostname example.com </dev/null 2>/dev/null | grep "Verify return code"
harmless

Convert a certificate and key from PEM to PFX

$openssl pkcs12 -export -out example.com.pfx -inkey example.com.key -in example.com.crt -certfile chain.pem
caution

Convert a PFX file to PEM with certificate and key

$openssl pkcs12 -in example.com.pfx -out example.com.pem -nodes
caution

Create a self-signed certificate for testing

$openssl req -x509 -newkey rsa:2048 -nodes -days 365 -keyout test.key -out test.crt -subj "/CN=test.example.com" -addext "subjectAltName=DNS:test.example.com"
caution

Generate a private key and CSR for multiple domains

$openssl req -new -newkey rsa:2048 -nodes -keyout example.com.key -out example.com.csr -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com"
caution

Read all domains of a certificate (SAN)

$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltName
harmless

Show all certbot certificates with domains and expiry dates

#certbot certificates
harmless

Show the certificate chain a server delivers

$openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null 2>/dev/null | grep -E "^ *([0-9]+ s:|i:)"
harmless

Show the expiry date and subject of a certificate file

#openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -subject -issuer -enddate
harmless

Show the SHA-256 fingerprint of a certificate

$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256
harmless

Test the renewal of all Let's Encrypt certificates (certbot)

#certbot renew --dry-run
harmless

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.