↑ ↓ select, Enter open, Esc close

Read all domains of a certificate (SAN)

Adjust the values, the command updates live
user@server
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltName

Fetches the certificate from the server and prints the subjectAltName extension, for example DNS:example.com, DNS:www.example.com. Browsers only check this list now, not the common name. If a variant such as www or a subdomain is missing, the browser shows a certificate warning.

Note: The -ext option requires OpenSSL 1.1.1 or newer. On older systems use -text and look for Subject Alternative Name.

Also searched as

  • which domains does an ssl certificate cover
  • show subject alternative names openssl
  • certificate not valid for www
  • NET::ERR_CERT_COMMON_NAME_INVALID

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.