Read all domains of a certificate (SAN)
which domains does an ssl certificate cover | show subject alternative names openssl | certificate not valid for www | NET::ERR_CERT_COMMON_NAME_INVALID | openssl | certificate | san | domainsopenssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltNameFetches the certificate from the server and prints the subjectAltName extension, for example DNS:example.com, DNS:www.example.com. Browsers only check this list now, not the common name. If a variant such as www or a subdomain is missing, the browser shows a certificate warning.
Note: The -ext option requires OpenSSL 1.1.1 or newer. On older systems use -text and look for Subject Alternative Name.
Also searched as
- which domains does an ssl certificate cover
- show subject alternative names openssl
- certificate not valid for www
- NET::ERR_CERT_COMMON_NAME_INVALID