1 2
DOMAIN=<domain> openssl s_client -connect $DOMAIN:443 -showcerts </dev/null | openssl x509 -outform pem > $DOMAIN.pem
-text
openssl x509 -in <file> -noout -text openssl x509 -in domain.pem -noout -text
-ext <extension>
-ext
<extension>
openssl x509 -in <file> -noout -ext subjectAltName openssl x509 -in <file> -noout -ext keyUsage
-issuer
1
openssl x509 -in <file> -noout -issuer
-serial
openssl x509 -in <file> -noout -serial
-subject
openssl x509 -in <file> -noout -subject
1 2 3 4
openssl x509 -in <file> -noout -fingerprint openssl x509 -in <file> -noout -fingerprint -md5 openssl x509 -in <file> -noout -fingerprint -sha1 openssl x509 -in <file> -noout -fingerprint -sha256