↑ ↓ select, Enter open, Esc close

Show the SHA-256 fingerprint of a certificate

Adjust the values, the command updates live
user@server
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256

Calculates the unique SHA-256 fingerprint of the delivered certificate. Useful after replacing a certificate to determine reliably whether the server already sends the new one or still the old one held in memory by a service that was not reloaded. For comparison, openssl x509 -in datei.pem -noout -fingerprint -sha256 gives the value of the local file.

Also searched as

  • show ssl certificate fingerprint
  • is the new certificate already being served
  • sha256 fingerprint openssl

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.