Cheatsheet: OpenSSL

Last updated 2026-09-29

Private Keys

Generate a 2048-bit RSA private key

openssl genrsa -out key.pem 2048

Generate an EC (elliptic curve) private key

openssl ecparam -genkey -name prime256v1 -out key.pem

Encrypt an existing private key with a passphrase

openssl rsa -in key.pem -aes256 -out key.enc.pem

Extract the public key from a private key

openssl rsa -in key.pem -pubout -out pubkey.pem

CSRs & Certificates

Generate a CSR from an existing private key

openssl req -new -key key.pem -out request.csr

Generate a key + CSR in one step

openssl req -new -newkey rsa:2048 -nodes -keyout key.pem -out request.csr

Create a self-signed certificate valid for 365 days

openssl req -x509 -new -key key.pem -days 365 -out cert.pem

One-liner: self-signed key + cert together

openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365

Add Subject Alternative Names non-interactively

openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com,DNS:www.example.com"

Inspecting & Verifying

Print full certificate details

openssl x509 -in cert.pem -noout -text

Show just the validity dates / subject / issuer

openssl x509 -in cert.pem -noout -dates
openssl x509 -in cert.pem -noout -subject
openssl x509 -in cert.pem -noout -issuer

Print CSR details

openssl req -in request.csr -noout -text

Verify a certificate against a CA bundle

openssl verify -CAfile ca-bundle.pem cert.pem

Confirm a private key and certificate belong to the same pair (compare the hashes)

openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5

TLS Handshake Testing

Connect to a server and dump its certificate chain + negotiated TLS version

openssl s_client -connect example.com:443 -servername example.com

Show the entire chain the server presented, not just the leaf

openssl s_client -connect example.com:443 -servername example.com -showcerts

Check just the remote certificate's expiry

echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates

Force a specific TLS version for the test connection

openssl s_client -connect example.com:443 -tls1_2

Format Conversions

Convert a certificate from PEM to DER (binary)

openssl x509 -in cert.pem -outform der -out cert.der

Convert a certificate from DER back to PEM

openssl x509 -in cert.der -inform der -outform pem -out cert.pem

Bundle a key + certificate into a password-protected PKCS#12 file

openssl pkcs12 -export -inkey key.pem -in cert.pem -out bundle.p12

Extract the private key and certificate back out of a PKCS#12 file

openssl pkcs12 -in bundle.p12 -nocerts -out key.pem
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out cert.pem

FAQ