⚙️ OpenSSL Command Cheat Sheet

Search or browse the most commonly needed OpenSSL commands for certificates and keys.

Eighteen commands, filtered as you type

This page runs nothing and sends nothing; it is a fixed list, and the filter tests both the description and the command text, so x509, pkcs12 and convert all narrow it. Copy a line, change the filenames, run it locally.

Flags worth adding before you run them

Stripping a passphrase leaves a key that anyone who can read the file can use. That is normally what a web server needs, so pair it with chmod 600 and an owner the service account alone can read.

Frequently asked questions

Why is my self-signed certificate still untrusted in Chrome?

Two separate reasons. Without a subjectAltName the name never matches, whatever you typed at the Common Name prompt. And even with it, nothing signed the certificate but itself, so the CA must be added to the machine's trust store before the warning goes away.

How do I remove the passphrase from a private key?

openssl rsa -in encrypted.key -out decrypted.key, entering the passphrase when prompted. For an EC or PKCS#8 key use openssl pkey with the same arguments; rsa handles RSA only.

How do I test which TLS versions a server supports?

Force one at a time: openssl s_client -connect example.com:443 -tls1_2, then -tls1_3. A completed handshake means it is accepted. Recent OpenSSL builds refuse to offer TLS 1.0 and 1.1 at all, so a failure there may be your client rather than the server.