OpenSSL速查手册
证书生成/查看/格式转换命令速查
📜 生成自签证书
同时生成 RSA 私钥与 x509 证书;-nodes 表示私钥不加密。
openssl req -x509 -newkey rsa:2048 -nodes \
-keyout key.pem -out cert.pem -days 365 \
-subj "/C=CN/ST=Beijing/L=Beijing/O=Demo/OU=Dev/CN=example.com/emailAddress=admin@example.com"
现代浏览器只信 SAN 不再信 CN;OpenSSL 1.1.1+ 可用 -addext 一步完成。
openssl req -x509 -newkey rsa:2048 -nodes \
-keyout key.pem -out cert.pem -days 825 \
-subj "/CN=example.com" \
-addext "subjectAltName=DNS:example.com,DNS:*.example.com,IP:127.0.0.1" \
-addext "extendedKeyUsage=serverAuth"
s_client 抓取对端证书链;SNI 多域名站点务必加 -servername。
openssl s_client -connect example.com:443 -servername example.com </dev/null
# 只导出站点证书
openssl s_client -connect example.com:443 -servername example.com \
-showcerts </dev/null 2>/dev/null | openssl x509 -out site.pem
# 指定 CA 校验
openssl s_client -connect example.com:443 -CAfile ca.pem </dev/null
🔍 查看证书
查看版本、序列号、颁发者、有效期、公钥、签名算法、扩展项。
openssl x509 -in cert.pem -text -noout | less
openssl x509 -in cert.pem -text -noout | grep -A1 "Signature Algorithm"
只看主题/颁发者/起止日期;脚本里判断是否过期很方便。
openssl x509 -in cert.pem -subject -issuer -dates -noout
openssl x509 -in cert.pem -startdate -enddate -noout
openssl x509 -in cert.pem -serial -noout
openssl x509 -in cert.pem -noout -enddate
# notAfter=Feb 10 12:00:00 2027 GMT
排查域名不匹配时直接看 subjectAltName。
openssl x509 -in cert.pem -ext subjectAltName -noout
openssl x509 -in cert.pem -ext extendedKeyUsage -noout
openssl x509 -in cert.pem -ext basicConstraints -noout
📝 CSR 证书签名请求
提交给 CA 签发;-subj 免去交互问答。
openssl req -new -newkey rsa:2048 -nodes \
-keyout example.key -out example.csr \
-subj "/C=CN/O=Demo Inc/CN=example.com"
# 已有私钥时创建 CSR
openssl req -new -key example.key -out example.csr \
-subj "/C=CN/O=Demo Inc/CN=example.com"
CSR 里的 SAN 必须通过 req_extensions 配置写入。
# openssl.cnf
[req]
default_bits = 2048
prompt = no
distinguished_name = req_dn
req_extensions = v3_req
[req_dn]
C = CN
O = Demo Inc
CN = example.com
[v3_req]
subjectAltName = @alt_names
[alt_names]
DNS.1 = example.com
DNS.2 = *.example.com
IP.1 = 127.0.0.1
# 生成命令
openssl req -new -key example.key -out example.csr -config openssl.cnf
提交 CA 前确认主题、SAN、公钥长度无误。
openssl req -in example.csr -text -noout
openssl req -in example.csr -subject -noout
openssl req -in example.csr -verify -noout
openssl req -in example.csr -pubkey -noout | openssl md5
🔑 私钥
genrsa 默认输出传统 PKCS#1(BEGIN RSA PRIVATE KEY);genpkey 输出 PKCS#8(BEGIN PRIVATE KEY)。
openssl genrsa -out rsa_pkcs1.key 2048
openssl genpkey -algorithm RSA -out rsa_pkcs8.key \
-pkeyopt rsa_keygen_bits:2048
# 查看头部确认格式
head -1 rsa_pkcs1.key # -----BEGIN RSA PRIVATE KEY-----
head -1 rsa_pkcs8.key # -----BEGIN PRIVATE KEY-----
prime256v1(P-256)最常用,密钥更短、握手更快。
openssl ecparam -name prime256v1 -genkey -noout -out ec.key
openssl ecparam -name secp384r1 -genkey -noout -out ec384.key
openssl ecparam -list_curves
# 查看曲线与公钥参数
openssl ec -in ec.key -text -noout | head -20
部分 Java/云平台只接受 PKCS#8;-traditional 回到 PKCS#1。
# PKCS#1 -> PKCS#8(不加密)
openssl pkcs8 -topk8 -nocrypt \
-in rsa_pkcs1.key -out rsa_pkcs8.key
# PKCS#1 -> PKCS#8(加密,AES-256)
openssl pkcs8 -topk8 -v2 aes-256-cbc \
-in rsa_pkcs1.key -out rsa_pkcs8_enc.key
# PKCS#8 -> PKCS#1(新版 OpenSSL)
openssl rsa -in rsa_pkcs8.key -traditional -out rsa_pkcs1.key
用 -aes256 加密落盘;去口令时会提示输入原密码。
# 给私钥加口令
openssl rsa -aes256 -in key.pem -out key.enc.pem
# 去除口令
openssl rsa -in key.enc.pem -out key.plain.pem
# 修改口令:先去再加(或直接转换到新文件)
openssl rsa -aes192 -in key.enc.pem -out key.new.pem
-check 校验 RSA 内部参数一致性;-modulus 可与证书比对。
openssl rsa -in key.pem -check -noout
# RSA key ok
openssl ec -in ec.key -check -noout
openssl rsa -in key.pem -noout -modulus
openssl rsa -in key.pem -pubout -out pub.pem
🔄 格式转换
PEM 是 Base64 文本(-----BEGIN-----),DER 是二进制 ASN.1。
# PEM:可直接文本打开,Apache/Nginx/负载均衡常用
# -----BEGIN CERTIFICATE-----
# MIIDXTCCAkWgAwIBAgIJ...
# -----END CERTIFICATE-----
# DER:二进制,部分 Java/Windows 组件使用
# PFX/P12:PKCS#12 容器,可同时装私钥+证书+链,通常带密码
# P7B/P7C:PKCS#7,只含证书链不含私钥
x509 转证书,rsa 转私钥(私钥推荐 pkcs8)。
openssl x509 -in cert.pem -outform der -out cert.der
openssl rsa -in key.pem -outform der -out key.der
关键在 -inform der 指定输入格式。
openssl x509 -inform der -in cert.der -out cert.pem
openssl rsa -inform der -in key.der -out key.pem
Windows/IIS、Tomcat 常要 PFX;建议把中间证书一起打入。
openssl pkcs12 -export \
-inkey key.pem \
-in cert.pem \
-certfile chain.pem \
-out bundle.p12 \
-name "example.com" \
-passout pass:123456
-nocerts 只取私钥,-clcerts -nokeys 只取用户证书。
# 全部导出(含 Bag 属性)
openssl pkcs12 -in bundle.p12 -nodes -out all.pem
# 只取私钥
openssl pkcs12 -in bundle.p12 -nodes -nocerts -out key.pem
# 只取证书(不含 CA)
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out cert.pem
# 只取 CA 链
openssl pkcs12 -in bundle.p12 -cacerts -nokeys -chain -out chain.pem
Windows 导出的 .p7b 只有证书不含私钥,需要先转成 PEM。
# P7B -> PEM(可能含多张证书)
openssl pkcs7 -in cert.p7b -print_certs -out cert.pem
openssl pkcs7 -inform der -in cert.p7b -print_certs -out cert.pem
# PEM -> P7B
openssl crl2pkcs7 -nocrl -certfile cert.pem -certfile chain.pem -out cert.p7b
✅ 校验与匹配
-CAfile 指定受信根;-untrusted 给中间证书。
openssl verify -CAfile ca.pem cert.pem
openssl verify -CAfile ca.pem -untrusted chain.pem cert.pem
# cert.pem: OK
# 查看系统时间下证书是否过期
openssl x509 -in cert.pem -checkend 0 -noout
openssl x509 -in cert.pem -checkend 2592000 -noout # 30 天内是否到期
分别取 modulus 的 MD5,两值一致即为一对;CSR 可一并比对。
openssl x509 -noout -modulus -in cert.pem | openssl md5
openssl rsa -noout -modulus -in key.pem | openssl md5
openssl req -noout -modulus -in example.csr | openssl md5
# 三者 MD5 相同则证书、私钥、CSR 相互匹配
老版 Nginx/Apache 前向保密配置使用,2048 位起步。
openssl dhparam -out dhparams.pem 2048
openssl dhparam -in dhparams.pem -text -noout | head
🆔 指纹与 SAN 检查
HPKP/云平台白名单/人工核对证书时使用。
openssl x509 -in cert.pem -fingerprint -sha1 -noout
openssl x509 -in cert.pem -fingerprint -sha256 -noout
openssl x509 -in cert.pem -fingerprint -sha256 -noout | cut -d= -f2 | tr -d :
# 公钥固定(SPKI)指纹,比证书指纹更稳
openssl x509 -in cert.pem -pubkey -noout \
| openssl pkey -pubin -outform der \
| openssl dgst -sha256 -binary | openssl enc -base64
证书报 NET::ERR_CERT_COMMON_NAME_INVALID 时检查这里。
openssl x509 -in cert.pem -noout -text \
| grep -A1 "Subject Alternative Name"
# X509v3 Subject Alternative Name:
# DNS:example.com, DNS:*.example.com, IP Address:127.0.0.1
# 一行快速查看
openssl x509 -in cert.pem -ext subjectAltName -noout -nameopt multiline
🔓 提取公钥
x509 从证书取,rsa/pkey 从私钥取,输出为 SPKI PEM。
# 从证书提取公钥
openssl x509 -in cert.pem -pubkey -noout > pub.pem
# 从 RSA / 通用私钥提取公钥
openssl rsa -in key.pem -pubout -out pub.pem
openssl pkey -in key.pem -pubout -out pub.pem
# 从 EC 私钥提取
openssl ec -in ec.key -pubout -out ec-pub.pem
-pubin 表示输入本身是公钥;可看指数、模数、曲线点。
openssl rsa -pubin -in pub.pem -text -noout
openssl pkey -pubin -in pub.pem -text -noout
openssl ec -pubin -in ec-pub.pem -text -noout
# PEM 公钥 -> DER
openssl rsa -pubin -in pub.pem -outform der -out pub.der
# 计算公钥指纹
openssl pkey -pubin -in pub.pem -outform der | openssl sha256
😶 没有匹配的条目,换个关键词试试
📖 使用说明
全程在浏览器本地运行。
操作步骤:
- 搜索或浏览分类条目;
- 查看命令说明;
- 点击复制命令。
💬 用户评论 (0)
还没有评论,快来抢沙发!