OpenSSL: Difference between revisions
m Text replacement - "Category:Linux " to "Category:Linux{{Navbox Linux}} " |
|||
| Line 75: | Line 75: | ||
* [[Self Signed SSL Certificates]] | * [[Self Signed SSL Certificates]] | ||
[[Category:Linux]] | [[Category:Linux]]{{Navbox Linux}} | ||
[[Category:LinuxUtilities]] | [[Category:LinuxUtilities]] | ||
{{Navbox Linux}} | {{Navbox Linux}} | ||
Revision as of 03:55, 1 September 2019
General OpenSSL Commands
These commands allow you to generate CSRs, Certificates, Private Keys and do other miscellaneous tasks.
Generate a new private key and Certificate Signing Request
openssl req -out CSR.csr -new -newkey rsa:2048 -nodes -keyout privateKey.key
Generate a self-signed certificate (see How to Create and Install an Apache Self Signed Certificate for more info)
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout privateKey.key -out certificate.crt
Generate a certificate signing request (CSR) for an existing private key
openssl req -out CSR.csr -key privateKey.key -new
Generate a certificate signing request based on an existing certificate
openssl x509 -x509toreq -in certificate.crt -out CSR.csr -signkey privateKey.key
Remove a passphrase from a private key
openssl rsa -in privateKey.pem -out newPrivateKey.pem
Checking Using OpenSSL
If you need to check the information within a Certificate, CSR or Private Key, use these commands. You can also check CSRs and check certificates using our online tools.
Check a Certificate Signing Request (CSR)
openssl req -text -noout -verify -in CSR.csr
Check a private key
openssl rsa -in privateKey.key -check
Check a certificate
openssl x509 -in certificate.crt -text -noout
Check a PKCS#12 file (.pfx or .p12)
openssl pkcs12 -info -in keyStore.p12
Debugging Using OpenSSL
If you are receiving an error that the private doesn't match the certificate or that a certificate that you installed to a site is not trusted, try one of these commands. If you are trying to verify that an SSL certificate is installed correctly, be sure to check out the SSL Checker.
Check an MD5 hash of the public key to ensure that it matches with what is in a CSR or private key
openssl x509 -noout -modulus -in certificate.crt | openssl md5 openssl rsa -noout -modulus -in privateKey.key | openssl md5 openssl req -noout -modulus -in CSR.csr | openssl md5
Check an SSL connection. All the certificates (including Intermediates) should be displayed
openssl s_client -connect www.paypal.com:443
Converting Using OpenSSL
These commands allow you to convert certificates and keys to different formats to make them compatible with specific types of servers or software. For example, you can convert a normal PEM file that would work with Apache to a PFX (PKCS#12) file and use it with Tomcat or IIS. Use our SSL Converter to convert certificates without messing with OpenSSL.
Convert a DER file (.crt .cer .der) to PEM
openssl x509 -inform der -in certificate.cer -out certificate.pem
Convert a PEM file to DER
openssl x509 -outform der -in certificate.pem -out certificate.der
Convert a PKCS#12 file (.pfx .p12) containing a private key and certificates to PEM
openssl pkcs12 -in keyStore.pfx -out keyStore.pem -nodes
You can add -nocerts to only output the private key or add -nokeys to only output the certificates.
Convert a PEM certificate file and a private key to PKCS#12 (.pfx .p12)
openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt
See Also
- https://www.sslshopper.com/article-most-common-openssl-commands.html
- Self Signed SSL Certificates
Various Linux Notes - /etc/fstab
- Access.conf
- ACL
- Apache Proxy to Internal Server
- APM X-C1 (Mustang)
- ARP
- Authselect
- Bash Scripting
- Blockparser
- Booting Linux without a Graphics Card
- Building Container Images
- Burning CD/DVD in Linux
- Clear RAID Signatures on Linux
- Cobbler
- Colorized Terminal Outputs
- Compiling MIPS
- Configure Sendmail
- CPanel
- CPanel Fork Bomb Protection
- CPU Frequency Scaling
- Create a Linux User with an Empty Password
- Cron and PAM Issues
- Dell OpenManage
- Diff Two Command Outputs
- DirectAdmin
- Disable Filesystem Check on Startup
- DNS Ad Blocker
- Driver Disk
- Drop caches
- End / Home keys don't work in Terminal
- Entropy in the Linux Kernel
- Entropy Source using RTL-SDR
- Exit Codes
- Extract .exe Resources with dd
- File Attributes
- Fixing ixgbe unsupported SFP+ module type was detected
- Get Active Linux Virtual Console
- Getting Hardware UUID
- Hosts.deny
- How to change Linux desktop user directories
- How to hot-swap SATA disks on Linux
- HP Smart Storage Administrator
- Hyper-threading
- IBM Spectrum Archive
- IBM Spectrum Protect
- IBM Tape
- IBM Tape Diagnostic Tool
- InterWorx
- Kerberize NFS
- Kerberize SSH
- Linux Clustering
- Linux Fonts
- Linux Namespaces
- Linux Network Interface Naming
- Linux Nvidia Driver
- Linux Process Accounting
- Linux Uptime in Seconds
- Linux UTF-8 Font
- Mainline Kernel on CentOS 7
- Missing Fonts
- Mod fastcgi Install on Apache 2 / cPanel
- Mod fcgid
- Monitoring network traffic in Linux
- Mounting / Unmounting KVM Image
- Mounting Samba (CIFS) shares
- Multiple Networks on Linux
- MySQL Database with Hash Sign
- No Console Output
- Number of Files Opened
- Open OnDemand
- Packing and unpacking initrd
- PAM Issues
- Partition Alignment
- Patching a binary file with dd
- Perl Module Location
- Raspberry Pi
- Red Hat kickstart
- Red Hat to Debian
- Reverse SSH Tunnel
- Ruby on Rails under cPanel
- Rutorrent + rtorrent Installation Guide on CentOS 6.4
- Self Signed SSL Certificates
- Service Management
- Sick Beard
- StartSSL Free Certificate
- Symlink
- Taking a Screenshot in X11
- Timezone
- Tor
- TOR Transparent Proxy
- Traefik
- Troubleshooting a Slow Linux System
- Turning on swap with a page file
- Udev Rules
- Verify SSL Certificate matches Private Key
- VMware Workstation
- Webcam
- X Display Manipulation
- X Forwarding
Linux Tools and Utilites - Anaconda
- Ansible
- Aria2
- Autofs
- Awk
- Badblocks
- Bash Shell
- Binwalk
- Bosh
- Ceph
- Chntpw
- Chrony
- Clonezilla
- Cloud-init
- CloudStack
- Column
- Cron
- Curl
- Cvs2git
- Date
- Dbus
- Dd
- Dm-crypt
- Dovecot
- DRBD
- ElasticSearch
- Enroot
- Environment Module
- Envsubst
- Fail2ban
- FFmpeg
- Find
- Firecracker
- Flashrom
- Foreman
- FortiClient
- Fswebcam
- Galaxy
- Git
- Gnome
- Gobetween
- GPFS
- Grafana
- Grub
- Hdparm
- Home Assistant
- How to disable SELinux
- Htaccess
- Infiniband
- InfluxDB
- InfluxDB 1.x
- Insert a kickstart file into a iso image
- Inspircd
- IOzone
- Iperf3
- Ipmitool
- Irqbalance
- John The Ripper
- Lightdm
- Lm sensors
- Logrotate
- LSF
- LVM
- Lynx
- Mailx
- Md5sum
- Mdadm
- Midnight Commander
- Motion
- Mount
- Mutt
- Nomad
- OpenLDAP
- Openocd
- OpenSSL
- OpenVPN
- Packer
- PHP
- Pi-hole
- Postgres
- PowerBroker Identity Service
- Proxmox
- Pueue
- PulseAudio
- Puppet
- Quota
- Red Hat Satellite
- Restic
- Rsync
- Rtorrent
- Ruby
- Sabnzbd
- Sage
- Samba
- Screen
- Sed
- SELinux
- Sendmail
- Shell Configs
- Singularity
- Sleep
- Slurm
- SMART
- Sonarr
- Sqlite
- SquashFS
- Squid
- SSH
- Steam
- Stoken
- Strace
- Sudo
- Sync
- Sysctl
- Syslog
- Sysrq
- System Security Services Daemon (SSSD)
- Systemd
- Tar
- Tcsh
- Telegraf
- Terraform
- Thttpd
- Tmux
- Tomcat
- Top
- Umask
- Unix2dos
- Vim
- Virsh
- Virt-customize
- VirtualBox
- VirtualGL
- Visidata
- Vnstat
- Weechat
- Wget
- XFS
- Youtube-dl
- ZFS
- Zram
Package Management Linux Distributions Networking - Blazemeter
- CSF/LFD
- Exim
- Firewall
- FreeIPA
- Get DHCP Network Settings
- IP Aliasing
- Ipset
- IPTables
- IPv6
- IPXE
- Link Aggregation
- Linux Network Namespaces
- MTU
- Net-tools to iproute2
- Netcat
- Open vSwitch
- OpenWRT
- Postfix
- Raspberry Pi Torified Wifi
- Socat
- Static Routes
- StrongSwan
- Tcpdump
- Traffic Forwarder using IPTables
- Wi-Fi
- WireGuard
Containers