#certificate
10 one-liners with this tag.
All one-liners tagged certificate
Check the SSL certificate expiration date of a website
$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates
Check whether a certificate expires within the next days
#openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -checkend $(( 30 * 86400 )) && echo "noch gültig" || echo "läuft bald ab"
Check whether a private key matches a certificate
#openssl x509 -noout -modulus -in /etc/ssl/certs/example.com.crt | openssl md5 && openssl rsa -noout -modulus -in /etc/ssl/private/example.com.key | openssl md5
Check whether a website's certificate is trusted
$openssl s_client -connect example.com:443 -servername example.com -verify_hostname example.com </dev/null 2>/dev/null | grep "Verify return code"
Create a self-signed certificate for testing
$openssl req -x509 -newkey rsa:2048 -nodes -days 365 -keyout test.key -out test.crt -subj "/CN=test.example.com" -addext "subjectAltName=DNS:test.example.com"
List the SSL certificates of a domain in Plesk
#plesk bin certificate --list -domain example.com
Read all domains of a certificate (SAN)
$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltName
Show the expiry date and subject of a certificate file
#openssl x509 -in /etc/letsencrypt/live/example.com/cert.pem -noout -subject -issuer -enddate
Show the SHA-256 fingerprint of a certificate
$openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -fingerprint -sha256
Test an SMTP connection with STARTTLS and certificate
$openssl s_client -connect mail.example.com:587 -starttls smtp -servername mail.example.com