⚙️ OpenSSL Command Cheat Sheet
Search or browse the most commonly needed OpenSSL commands for certificates and keys.
Eighteen commands, filtered as you type
This page runs nothing and sends nothing; it is a fixed list, and the filter tests
both the description and the command text, so x509,
pkcs12 and convert all narrow it. Copy a line, change the
filenames, run it locally.
Flags worth adding before you run them
- The self-signed line produces a certificate no browser will accept.
It fills in only a common name, and clients have ignored CN since 2017. Append
-addext "subjectAltName=DNS:localhost,IP:127.0.0.1"so the name actually appears where it is checked. ecparam -genkeywrites two PEM blocks, an EC PARAMETERS block followed by the key, and some servers reject the file for it. Adding-nooutsuppresses the parameters and leaves the key alone.- Encrypting with
openssl rsa -aes256uses the old PKCS#1 format with Proc-Type headers. For the modern container useopenssl pkcs8 -topk8 -v2 aes-256-cbc -in private.key -out encrypted.key, which encrypts to PKCS#8 and works for EC keys too. - The modulus line is half a comparison. Hash the key the same way and check the two outputs are identical - and note that RSA is the only algorithm with a modulus to hash.
chmod 600 and an owner the service account alone can read.Frequently asked questions
Why is my self-signed certificate still untrusted in Chrome?
Two separate reasons. Without a subjectAltName the name never matches, whatever you typed at the Common Name prompt. And even with it, nothing signed the certificate but itself, so the CA must be added to the machine's trust store before the warning goes away.
How do I remove the passphrase from a private key?
openssl rsa -in encrypted.key -out decrypted.key, entering the
passphrase when prompted. For an EC or PKCS#8 key use openssl pkey
with the same arguments; rsa handles RSA only.
How do I test which TLS versions a server supports?
Force one at a time: openssl s_client -connect example.com:443 -tls1_2,
then -tls1_3. A completed handshake means it is accepted. Recent
OpenSSL builds refuse to offer TLS 1.0 and 1.1 at all, so a failure there may be
your client rather than the server.