↑ ↓ select, Enter open, Esc close

Show the expiry date and subject of a certificate file

Adjust the values, the command updates live
root@server
openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -subject -issuer -enddate

Reads a certificate file in PEM format and prints the subject, issuer and notAfter. Useful to see quickly which certificate is meant for what and for how long, before installing it or when sorting through a collection of files. Use -text instead of the individual options to see all details.

Note: Root is only needed if the file is protected, as under /etc/letsencrypt/. For DER files, add -inform der.

Also searched as

  • check certificate file expiration
  • crt file expiry date openssl
  • which domain is this certificate for
  • show pem certificate details

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.