首页 / 速查手册 / 在线

OpenSSL速查手册

证书生成/查看/格式转换命令速查

速查手册 · 1 次 · 2026-10-04 · 分享 · 全屏

📜 生成自签证书

一条命令生成自签证书

同时生成 RSA 私钥与 x509 证书;-nodes 表示私钥不加密。

openssl req -x509 -newkey rsa:2048 -nodes \
  -keyout key.pem -out cert.pem -days 365 \
  -subj "/C=CN/ST=Beijing/L=Beijing/O=Demo/OU=Dev/CN=example.com/emailAddress=admin@example.com"
带 SAN 的自签证书(推荐)

现代浏览器只信 SAN 不再信 CN;OpenSSL 1.1.1+ 可用 -addext 一步完成。

openssl req -x509 -newkey rsa:2048 -nodes \
  -keyout key.pem -out cert.pem -days 825 \
  -subj "/CN=example.com" \
  -addext "subjectAltName=DNS:example.com,DNS:*.example.com,IP:127.0.0.1" \
  -addext "extendedKeyUsage=serverAuth"
查看远端网站证书

s_client 抓取对端证书链;SNI 多域名站点务必加 -servername。

openssl s_client -connect example.com:443 -servername example.com </dev/null

# 只导出站点证书
openssl s_client -connect example.com:443 -servername example.com \
  -showcerts </dev/null 2>/dev/null | openssl x509 -out site.pem

# 指定 CA 校验
openssl s_client -connect example.com:443 -CAfile ca.pem </dev/null

🔍 查看证书

完整内容 -text

查看版本、序列号、颁发者、有效期、公钥、签名算法、扩展项。

openssl x509 -in cert.pem -text -noout | less
openssl x509 -in cert.pem -text -noout | grep -A1 "Signature Algorithm"
摘要信息

只看主题/颁发者/起止日期;脚本里判断是否过期很方便。

openssl x509 -in cert.pem -subject -issuer -dates -noout
openssl x509 -in cert.pem -startdate -enddate -noout
openssl x509 -in cert.pem -serial -noout
openssl x509 -in cert.pem -noout -enddate
# notAfter=Feb 10 12:00:00 2027 GMT
查看 SAN 与用途扩展

排查域名不匹配时直接看 subjectAltName。

openssl x509 -in cert.pem -ext subjectAltName -noout
openssl x509 -in cert.pem -ext extendedKeyUsage -noout
openssl x509 -in cert.pem -ext basicConstraints -noout

📝 CSR 证书签名请求

生成新私钥并创建 CSR

提交给 CA 签发;-subj 免去交互问答。

openssl req -new -newkey rsa:2048 -nodes \
  -keyout example.key -out example.csr \
  -subj "/C=CN/O=Demo Inc/CN=example.com"

# 已有私钥时创建 CSR
openssl req -new -key example.key -out example.csr \
  -subj "/C=CN/O=Demo Inc/CN=example.com"
带 SAN 的 CSR(配置文件)

CSR 里的 SAN 必须通过 req_extensions 配置写入。

# openssl.cnf
[req]
default_bits       = 2048
prompt             = no
distinguished_name = req_dn
req_extensions     = v3_req

[req_dn]
C  = CN
O  = Demo Inc
CN = example.com

[v3_req]
subjectAltName = @alt_names

[alt_names]
DNS.1 = example.com
DNS.2 = *.example.com
IP.1  = 127.0.0.1

# 生成命令
openssl req -new -key example.key -out example.csr -config openssl.cnf
查看与验证 CSR

提交 CA 前确认主题、SAN、公钥长度无误。

openssl req -in example.csr -text -noout
openssl req -in example.csr -subject -noout
openssl req -in example.csr -verify -noout
openssl req -in example.csr -pubkey -noout | openssl md5

🔑 私钥

生成 RSA 私钥(PKCS#1 / PKCS#8)

genrsa 默认输出传统 PKCS#1(BEGIN RSA PRIVATE KEY);genpkey 输出 PKCS#8(BEGIN PRIVATE KEY)。

openssl genrsa -out rsa_pkcs1.key 2048

openssl genpkey -algorithm RSA -out rsa_pkcs8.key \
  -pkeyopt rsa_keygen_bits:2048

# 查看头部确认格式
head -1 rsa_pkcs1.key   # -----BEGIN RSA PRIVATE KEY-----
head -1 rsa_pkcs8.key   # -----BEGIN PRIVATE KEY-----
EC 椭圆曲线私钥

prime256v1(P-256)最常用,密钥更短、握手更快。

openssl ecparam -name prime256v1 -genkey -noout -out ec.key
openssl ecparam -name secp384r1 -genkey -noout -out ec384.key
openssl ecparam -list_curves

# 查看曲线与公钥参数
openssl ec -in ec.key -text -noout | head -20
PKCS#1 与 PKCS#8 互转

部分 Java/云平台只接受 PKCS#8;-traditional 回到 PKCS#1。

# PKCS#1 -> PKCS#8(不加密)
openssl pkcs8 -topk8 -nocrypt \
  -in rsa_pkcs1.key -out rsa_pkcs8.key

# PKCS#1 -> PKCS#8(加密,AES-256)
openssl pkcs8 -topk8 -v2 aes-256-cbc \
  -in rsa_pkcs1.key -out rsa_pkcs8_enc.key

# PKCS#8 -> PKCS#1(新版 OpenSSL)
openssl rsa -in rsa_pkcs8.key -traditional -out rsa_pkcs1.key
私钥加口令 / 去口令

用 -aes256 加密落盘;去口令时会提示输入原密码。

# 给私钥加口令
openssl rsa -aes256 -in key.pem -out key.enc.pem

# 去除口令
openssl rsa -in key.enc.pem -out key.plain.pem

# 修改口令:先去再加(或直接转换到新文件)
openssl rsa -aes192 -in key.enc.pem -out key.new.pem
检查私钥有效性

-check 校验 RSA 内部参数一致性;-modulus 可与证书比对。

openssl rsa -in key.pem -check -noout
# RSA key ok

openssl ec -in ec.key -check -noout
openssl rsa -in key.pem -noout -modulus
openssl rsa -in key.pem -pubout -out pub.pem

🔄 格式转换

PEM 与 DER 的区别

PEM 是 Base64 文本(-----BEGIN-----),DER 是二进制 ASN.1。

# PEM:可直接文本打开,Apache/Nginx/负载均衡常用
# -----BEGIN CERTIFICATE-----
# MIIDXTCCAkWgAwIBAgIJ...
# -----END CERTIFICATE-----

# DER:二进制,部分 Java/Windows 组件使用
# PFX/P12:PKCS#12 容器,可同时装私钥+证书+链,通常带密码
# P7B/P7C:PKCS#7,只含证书链不含私钥
PEM -> DER

x509 转证书,rsa 转私钥(私钥推荐 pkcs8)。

openssl x509 -in cert.pem -outform der -out cert.der
openssl rsa  -in key.pem  -outform der -out key.der
DER -> PEM

关键在 -inform der 指定输入格式。

openssl x509 -inform der -in cert.der -out cert.pem
openssl rsa  -inform der -in key.der  -out key.pem
导出 PFX / P12 容器

Windows/IIS、Tomcat 常要 PFX;建议把中间证书一起打入。

openssl pkcs12 -export \
  -inkey key.pem \
  -in cert.pem \
  -certfile chain.pem \
  -out bundle.p12 \
  -name "example.com" \
  -passout pass:123456
解析 PFX 取出证书与私钥

-nocerts 只取私钥,-clcerts -nokeys 只取用户证书。

# 全部导出(含 Bag 属性)
openssl pkcs12 -in bundle.p12 -nodes -out all.pem

# 只取私钥
openssl pkcs12 -in bundle.p12 -nodes -nocerts -out key.pem

# 只取证书(不含 CA)
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out cert.pem

# 只取 CA 链
openssl pkcs12 -in bundle.p12 -cacerts -nokeys -chain -out chain.pem
P7B 证书链转换

Windows 导出的 .p7b 只有证书不含私钥,需要先转成 PEM。

# P7B -> PEM(可能含多张证书)
openssl pkcs7 -in cert.p7b -print_certs -out cert.pem
openssl pkcs7 -inform der -in cert.p7b -print_certs -out cert.pem

# PEM -> P7B
openssl crl2pkcs7 -nocrl -certfile cert.pem -certfile chain.pem -out cert.p7b

✅ 校验与匹配

verify 验证证书链与有效期

-CAfile 指定受信根;-untrusted 给中间证书。

openssl verify -CAfile ca.pem cert.pem
openssl verify -CAfile ca.pem -untrusted chain.pem cert.pem
# cert.pem: OK

# 查看系统时间下证书是否过期
openssl x509 -in cert.pem -checkend 0 -noout
openssl x509 -in cert.pem -checkend 2592000 -noout   # 30 天内是否到期
证书与私钥是否匹配

分别取 modulus 的 MD5,两值一致即为一对;CSR 可一并比对。

openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa  -noout -modulus -in key.pem  | openssl md5
openssl req  -noout -modulus -in example.csr | openssl md5
# 三者 MD5 相同则证书、私钥、CSR 相互匹配
生成 DH 参数(旧套件加固)

老版 Nginx/Apache 前向保密配置使用,2048 位起步。

openssl dhparam -out dhparams.pem 2048
openssl dhparam -in dhparams.pem -text -noout | head

🆔 指纹与 SAN 检查

证书指纹

HPKP/云平台白名单/人工核对证书时使用。

openssl x509 -in cert.pem -fingerprint -sha1   -noout
openssl x509 -in cert.pem -fingerprint -sha256 -noout
openssl x509 -in cert.pem -fingerprint -sha256 -noout | cut -d= -f2 | tr -d :

# 公钥固定(SPKI)指纹,比证书指纹更稳
openssl x509 -in cert.pem -pubkey -noout \
  | openssl pkey -pubin -outform der \
  | openssl dgst -sha256 -binary | openssl enc -base64
核对 SAN 域名覆盖

证书报 NET::ERR_CERT_COMMON_NAME_INVALID 时检查这里。

openssl x509 -in cert.pem -noout -text \
  | grep -A1 "Subject Alternative Name"
# X509v3 Subject Alternative Name:
#     DNS:example.com, DNS:*.example.com, IP Address:127.0.0.1

# 一行快速查看
openssl x509 -in cert.pem -ext subjectAltName -noout -nameopt multiline

🔓 提取公钥

从证书或私钥提取公钥

x509 从证书取,rsa/pkey 从私钥取,输出为 SPKI PEM。

# 从证书提取公钥
openssl x509 -in cert.pem -pubkey -noout > pub.pem

# 从 RSA / 通用私钥提取公钥
openssl rsa  -in key.pem -pubout -out pub.pem
openssl pkey -in key.pem -pubout -out pub.pem

# 从 EC 私钥提取
openssl ec -in ec.key -pubout -out ec-pub.pem
查看公钥详情与转换

-pubin 表示输入本身是公钥;可看指数、模数、曲线点。

openssl rsa -pubin -in pub.pem -text -noout
openssl pkey -pubin -in pub.pem -text -noout
openssl ec  -pubin -in ec-pub.pem -text -noout

# PEM 公钥 -> DER
openssl rsa -pubin -in pub.pem -outform der -out pub.der

# 计算公钥指纹
openssl pkey -pubin -in pub.pem -outform der | openssl sha256

📖 使用说明

全程在浏览器本地运行。

操作步骤:

  1. 搜索或浏览分类条目;
  2. 查看命令说明;
  3. 点击复制命令。

💬 用户评论 (0)

还没有评论,快来抢沙发!

请添加微信联系我