在 Linux 下使用 OpenSSL 检查证书,常见场景和命令如下:
openssl x509 -in cert.crt -text -noout
或
openssl x509 -in cert.pem -text -noout
常用参数说明:
-text:以可读方式显示证书内容-noout:不输出编码后的证书本身可查看:
openssl x509 -in cert.crt -noout -dates
输出示例:
notBefore=May 1 00:00:00 2024 GMT
notAfter=May 1 23:59:59 2025 GMT
openssl x509 -in cert.crt -noout -fingerprint
SHA256 指纹:
openssl x509 -in cert.crt -noout -fingerprint -sha256
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -text -noout
只看基本信息:
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates -subject -issuer
指定 SNI(虚拟主机):
openssl s_client -connect example.com:443 -servername example.com
openssl s_client -connect example.com:443 -showcerts
或验证:
openssl verify -CAfile ca.crt cert.crt
openssl x509 -noout -modulus -in cert.crt | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
两个 MD5 值应一致。
openssl req -in req.csr -text -noout
如果你有 具体场景(如 Nginx、Kubernetes、自签证书、过期告警),可以告诉我,我可以给你更针对性的命令。