↑ ↓ select, Enter open, Esc close

Check whether a website's certificate is trusted

Adjust the values, the command updates live
user@server
openssl s_client -connect example.com:443 -servername example.com -verify_hostname example.com </dev/null 2>/dev/null | grep "Verify return code"

Verifies the delivered certificate against the system’s trusted certificate authorities and checks the hostname. 0 (ok) means everything is fine. Typical errors are 20 (unable to get local issuer certificate) for a missing intermediate certificate, 10 (certificate has expired) or 62 (hostname mismatch).

Note: On outdated systems, a CA missing from the local store can also cause code 20, in that case update ca-certificates.

Also searched as

  • check if ssl certificate is valid
  • unable to get local issuer certificate
  • certificate verify failed cause
  • certificate not trusted openssl

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.