How can I verify the details of an SSL certificate?

You can use openssl to view various certificate parameters.


[root@root certs]# openssl x509 -text -in test.pem

Certificate:

    Data:

        Version: 3 (0x2)

        Serial Number: 0 (0x0)

        Signature Algorithm: md5WithRSAEncryption

       
Issuer: C=US, ST=Texas, L=Dallas, O=My SSL Company, OU=RnD,
CN=localhost/emailAddress=root@localhost


        Validity

            Not Before: Nov 14 23:38:36 2005 GMT

            Not After : Nov 14 23:38:36 2006 GMT

       
Subject: C=US, ST=Texas, L=Dallas, O=My SSL Company, OU=RnD,
CN=localhost/emailAddress=root@localhost


        Subject Public Key Info:

            Public Key Algorithm: rsaEncryption

            RSA Public Key: (1024 bit)

                Modulus (1024 bit):

                   
00:fb:91:2f:3a:3b:26:60:51:a1:d8:2f:e7:f6:c3:


                   
3d:aa:66:ee:d0:9c:94:ea:73:03:19:4c:08:33:5c:


                   
21:7f:b5:35:2e:e1:ce:80:54:02:df:aa:05:47:71:


                   
d4:cc:b1:03:21:23:b2:3f:13:4a:ad:1e:9c:be:10:


                   
2d:7b:1a:1e:4a:ad:e8:e1:6a:46:29:1e:32:e9:3b:


                   
96:8e:00:c0:3a:d3:5e:44:80:21:1d:f6:c3:d8:6e:


                   
61:62:54:0e:f7:76:86:ef:0a:b9:51:e7:3a:0e:5f:


                   
dd:d5:86:d2:38:86:99:26:3d:c3:75:8a:20:fb:e9:


                   
52:e4:86:e9:45:ff:ec:f0:47


                Exponent: 65537 (0x10001)

        X509v3 extensions:

            X509v3 Subject Key Identifier:

            86:8F:2A:8F:00:66:A7:2F:7D:0E:56:0A:10:15:91:88:5C:B9:8C:44

            X509v3 Authority Key Identifier:

           
keyid:86:8F:2A:8F:00:66:A7:2F:7D:0E:56:0A:10:15:91:88:5C:B9:8C:44


           
DirName:/C=US/ST=Texas/L=Dallas/O=My SSL
Company/OU=RnD/CN=localhost/emailAddress=root@localhost


            serial:00



            X509v3 Basic Constraints:

            CA:TRUE

    Signature Algorithm: md5WithRSAEncryption

        b5:f8:31:9f:2c:7e:33:65:8f:00:aa:2b:07:ce:99:84:d3:60:

        97:0f:fb:58:17:f2:ad:06:7c:c0:70:e4:7a:b2:0d:e7:a2:67:

        77:2f:74:80:e4:4c:69:25:bc:69:71:44:7a:67:b4:12:07:9c:

        aa:c5:ed:fc:99:10:0d:11:fa:f6:88:45:e6:a9:60:ec:82:56:

        05:4a:79:cb:9b:eb:98:3c:11:9f:e0:ca:7b:ac:d9:ec:b4:8c:

        cc:70:40:93:65:d4:5f:1d:94:4c:49:08:9f:a5:09:8b:c2:fa:

        af:cb:5b:11:db:12:10:fb:c4:75:2f:89:22:ab:bb:74:2d:e1:

        1b:e0

——-BEGIN CERTIFICATE——-

MIIDcTCCAtqgAwIBAgIBADANBgkqhkiG9w0BAQQFADCBiDELMAkGA1UEBhMCVVMx

DjAMBgNVBAgTBVRleGFzMQ8wDQYDVQQHEwZEYWxsYXMxFzAVBgNVBAoTDk15IFNT

TCBDb21wYW55MQwwCgYDVQQLEwNSbkQxEjAQBgNVBAMTCWxvY2FsaG9zdDEdMBsG

CSqGSIb3DQEJARYOcm9vdEBsb2NhbGhvc3QwHhcNMDUxMTE0MjMzODM2WhcNMDYx

MTE0MjMzODM2WjCBiDELMAkGA1UEBhMCVVMxDjAMBgNVBAgTBVRleGFzMQ8wDQYD

VQQHEwZEYWxsYXMxFzAVBgNVBAoTDk15IFNTTCBDb21wYW55MQwwCgYDVQQLEwNS

bkQxEjAQBgNVBAMTCWxvY2FsaG9zdDEdMBsGCSqGSIb3DQEJARYOcm9vdEBsb2Nh

bGhvc3QwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAPuRLzo7JmBRodgv5/bD

Papm7tCclOpzAxlMCDNcIX+1NS7hzoBUAt+qBUdx1MyxAyEjsj8TSq0enL4QLXsa

Hkqt6OFqRikeMuk7lo4AwDrTXkSAIR32w9huYWJUDvd2hu8KuVHnOg5f3dWG0jiG

mSY9w3WKIPvpUuSG6UX/7PBHAgMBAAGjgegwgeUwHQYDVR0OBBYEFIaPKo8AZqcv

fQ5WChAVkYhcuYxEMIG1BgNVHSMEga0wgaqAFIaPKo8AZqcvfQ5WChAVkYhcuYxE

oYGOpIGLMIGIMQswCQYDVQQGEwJVUzEOMAwGA1UECBMFVGV4YXMxDzANBgNVBAcT

BkRhbGxhczEXMBUGA1UEChMOTXkgU1NMIENvbXBhbnkxDDAKBgNVBAsTA1JuRDES

MBAGA1UEAxMJbG9jYWxob3N0MR0wGwYJKoZIhvcNAQkBFg5yb290QGxvY2FsaG9z

dIIBADAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBAUAA4GBALX4MZ8sfjNljwCq

KwfOmYTTYJcP+1gX8q0GfMBw5HqyDeeiZ3cvdIDkTGklvGlxRHpntBIHnKrF7fyZ

EA0R+vaIReapYOyCVgVKecub65g8EZ/gynus2ey0jMxwQJNl1F8dlExJCJ+lCYvC

+q/LWxHbEhD7xHUviSKru3Qt4Rvg

——-END CERTIFICATE——-




If you only want specific information you can use one or more options:


[root@root certs]# openssl x509 -noout -in test.pem -issuer

issuer= /C=US/ST=Texas/L=Dallas/O=My SSL Company/OU=RnD/CN=localhost/emailAddress=root@localhost

[root@root certs]# openssl x509 -noout -in test.pem -subject

subject= /C=US/ST=Texas/L=Dallas/O=My SSL Company/OU=RnD/CN=localhost/emailAddress=root@localhost

[root@root certs]# openssl x509 -noout -in test.pem -dates

notBefore=Nov 14 23:38:36 2005 GMT

notAfter=Nov 14 23:38:36 2006 GMT

[root@root certs]# openssl x509 -noout -in test.pem -issuer -subject -dates

issuer= /C=US/ST=Texas/L=Dallas/O=My SSL Company/OU=RnD/CN=localhost/emailAddress=root@localhost

subject= /C=US/ST=Texas/L=Dallas/O=My SSL Company/OU=RnD/CN=localhost/emailAddress=root@localhost

notBefore=Nov 14 23:38:36 2005 GMT

notAfter=Nov 14 23:38:36 2006 GMT

[root@root certs]# openssl x509 -noout -in test.pem -fingerprint

MD5 Fingerprint=4E:37:1A:FD:82:0A:F7:C2:B7:04:CA:5F:51:7A:61:34

[root@root certs]# openssl x509 -noout -in test.pem -hash

cf0dddab

[root@root certs]#


Your rating: None