↑ ↓ select, Enter open, Esc close

Show the certificate chain a server delivers

Adjust the values, the command updates live
user@server
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null 2>/dev/null | grep -E "^ *([0-9]+ s:|i:)"

Lists the certificates sent by the server, numbered, each with subject (s:) and issuer (i:). In a complete chain, the issuer of number 0 is the subject of number 1, and so on. If the server sends only number 0, the intermediate certificate is missing: desktop browsers often fill it in silently, while smartphones, curl or payment providers report an error.

Also searched as

  • missing intermediate certificate
  • check ssl certificate chain
  • incomplete certificate chain
  • show certificate chain openssl s_client

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.