CmdKeys LogoCommand Quiz

OpenSSL Command Practice

OpenSSL is the Swiss Army knife of cryptography, used daily by sysadmins to manage PKI. This track focuses on the most practical subcommands (req, x509, rsa, pkcs12, s_client) so you can generate keys, inspect certificates, convert formats, and debug TLS connections without constantly searching for the syntax.

Command Reference

x509

CommandDescription
openssl x509 -in cert.pem -noout -subjectPrint only the subject (owner) Distinguished Name of an X.509 certificate.
openssl x509 -in cert.pem -noout -issuerPrint only the issuer (Certificate Authority) Distinguished Name of an X.509 certificate.
openssl x509 -in cert.pem -noout -textDisplay the full human-readable contents of an X.509 certificate, including subject, issuer, dates, and extensions.
openssl x509 -in cert.pem -noout -datesPrint only the valid-from (notBefore) and valid-to (notAfter) dates of a certificate to check for expiration.
openssl x509 -in cert.pem -noout -fingerprint -sha256Calculate and print the SHA-256 fingerprint (hash) of an X.509 certificate.
openssl x509 -in cert.pem -noout -modulusPrint the modulus of a certificate's public key — often compared against a private key's modulus to verify they match.

req

CommandDescription
openssl req -in my.csr -noout -textDisplay the human-readable contents of a Certificate Signing Request (CSR) to verify its subject and extensions.
openssl req -new -key key.pem -out csr.pemCreate a new Certificate Signing Request (CSR) using an existing private key.
openssl req -in my.csr -noout -verifyVerify the digital signature of a Certificate Signing Request (CSR) to ensure it was not tampered with.
openssl req -newkey rsa:2048 -nodes -keyout key.pem -out csr.pemGenerate a new 2048-bit RSA private key (without a passphrase) and a Certificate Signing Request (CSR) in one step.
openssl req -x509 -newkey rsa:2048 -nodes -keyout key.pem -out cert.pem -days 365Generate a new private key and a self-signed X.509 certificate valid for 365 days — useful for testing.

s_client

CommandDescription
openssl s_client -connect example.com:443 -briefConnect to a server and display only a brief summary of the negotiated cipher and TLS version.
openssl s_client -connect example.com:443Connect to an SSL/TLS server and display detailed connection parameters and the server certificate.
openssl s_client -connect example.com:443 -showcertsConnect to a server and print the entire PEM-encoded certificate chain presented by the server.
openssl s_client -connect mail.example.com:25 -starttls smtpConnect to an SMTP server and upgrade the plain-text connection to TLS using the STARTTLS command.
openssl s_client -connect example.com:443 -servername example.comConnect to a server using Server Name Indication (SNI) to request the certificate for a specific virtual host.

pkcs12

CommandDescription
openssl pkcs12 -in bundle.p12 -info -nooutDisplay information about the contents and structure of a PKCS#12 bundle without extracting keys.
openssl pkcs12 -export -in cert.pem -inkey key.pem -out bundle.p12Package a certificate and its corresponding private key into a PKCS#12 (.p12/.pfx) keystore bundle.
openssl pkcs12 -in bundle.p12 -nocerts -out key.pemExtract only the private key from a PKCS#12 bundle (skips certificates).
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out cert.pemExtract only the client certificate from a PKCS#12 bundle (skips the private key and CA certs).
openssl pkcs12 -export -in cert.pem -inkey key.pem -certfile chain.pem -out bundle.p12Package a certificate, private key, and the intermediate CA chain into a single PKCS#12 bundle.

rsa

CommandDescription
openssl rsa -in key.pem -aes256 -out enc.pemEncrypt an unencrypted RSA private key using AES-256 (prompts for a passphrase).
openssl rsa -in enc.pem -out dec.pemRemove the passphrase from an encrypted RSA private key (prompts for the current passphrase).
openssl rsa -in key.pem -pubout -out pubkey.pemExtract the public key from an RSA private key and save it to a new file.
openssl rsa -in key.pem -check -nooutCheck the mathematical consistency of an RSA private key to ensure it is not corrupted.
openssl rsa -in key.pem -noout -textPrint the mathematical components (modulus, primes, exponents) of an RSA private key in plain text.

Key Use Cases

  • Generate a new RSA private key and a Certificate Signing Request (CSR) with req
  • Inspect the validity dates, issuer, and subject of an x509 certificate
  • Remove or add a passphrase to an RSA private key
  • Package a certificate, private key, and CA chain into a PKCS#12 bundle for export
  • Connect to a remote server using s_client to view the certificate chain it presents
  • Verify the modulus of a private key and a certificate to ensure they match

Frequently Asked Questions

What is the difference between openssl req and openssl x509?

req is used for generating Certificate Signing Requests (CSRs) and new private keys. x509 is used for displaying and managing existing X.509 certificates. You use req to ask for a certificate, and x509 to inspect it once it's signed.

Why do I need -noout when inspecting a certificate?

By default, commands like openssl x509 and openssl req print the base64-encoded PEM string of the file to standard output. Adding -noout suppresses this, making it easier to read the specific fields you requested, such as -text or -dates.

What is a PKCS#12 (.p12 or .pfx) file?

PKCS#12 is an archive file format that bundles a private key, its corresponding certificate, and optionally the CA trust chain into a single, password-protected file. It is commonly used to import identities into Windows, macOS, or Java keystores.

How can I test if a mail server supports STARTTLS?

Use openssl s_client -connect mail.example.com:25 -starttls smtp. The -starttls flag tells s_client to speak the plain-text protocol initially and then issue the appropriate command (like STARTTLS) to upgrade the connection to TLS.

Ready to master OpenSSL commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →