↑ ↓ select, Enter open, Esc close

Check whether a private key matches a certificate

Adjust the values, the command updates live
root@server
openssl x509 -noout -modulus -in /etc/ssl/certs/example.com.crt | openssl md5 && openssl rsa -noout -modulus -in /etc/ssl/private/example.com.key | openssl md5

Prints two MD5 checksums, one for the modulus of the certificate and one for that of the private key. If both are identical, key and certificate belong together. If they differ, the web server will not start or reports key values mismatch.

Note: Only works with RSA keys. For ECDSA, compare the public keys instead: openssl x509 -noout -pubkey -in cert.pem against openssl pkey -pubout -in key.pem.

Also searched as

  • check private key matches certificate
  • key values mismatch apache
  • compare ssl key and certificate modulus
  • which key belongs to this certificate

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.