Home / Alt manpages / openssl-namedisplay-options(1ssl)

  • openssl-namedisplay-options(1ssl)
  • OpenSSL command
  • linux

Make OpenSSL Distinguished Names Readable with -nameopt

You will finish with repeatable OpenSSL commands for displaying certificate subject and issuer distinguished names (DNs) in a readable, multiline or RFC 2253 style. The examples use the openssl x509 command installed here as OpenSSL 3.0.13, from the Ubuntu package that provides the local openssl-namedisplay-options(1ssl) manual page. Allow about ten minutes. You need a shell and a readable PEM certificate.

1. Check the command and certificate

-nameopt is not a separate executable. It is an option accepted by OpenSSL commands that print subject or issuer names. The local manual describes the available name-format flags, while x509 supplies the certificate data.

$ command -v openssl
/usr/bin/openssl
$ /usr/bin/openssl version
OpenSSL 3.0.13 30 Jan 2024 (Library: OpenSSL 3.0.13 30 Jan 2024)
$ test -r /path/to/certificate.pem && echo readable
readable

Replace /path/to/certificate.pem with your certificate. These commands only read the certificate and write output to the terminal. They do not need sudo. If you have no test certificate, use a certificate from a non-sensitive test directory or a public CA certificate already installed on the machine.

2. See the default display

Start with the command's ordinary subject output. The name-display manual calls oneline the default and describes it as a readable one-line format. The visible field names are short names such as C, O and CN.

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject
subject=C = GB, O = Example Org, CN = example.test

Your values will differ. The subject= prefix comes from x509; -noout suppresses the certificate's PEM output so that only the requested field is printed. Add -issuer when you need the issuer instead:

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -issuer
issuer=C = GB, O = Example CA, CN = Example Issuing CA

3. Use multiline output when people need to read it

For incident notes, terminal checks and review logs, multiline separates fields and uses long names with indentation. It is a preset, not a request to wrap an already-rendered line.

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject -nameopt multiline
subject=
    countryName               = GB
    organizationName          = Example Org
    commonName                = example.test

The preset includes multiline separators, long field names, alignment and spaces around the equals sign. If you combine flags yourself, the equivalent practical form is:

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject \
    -nameopt sep_multiline,lname,align,space_eq

Keep the option spelling exact. The documented flag is lname, singular. A misspelled or unknown name option makes the installed x509 command reject the request rather than silently choosing a fallback.

4. Choose RFC 2253 output for machine-facing text

Use the RFC2253 preset when another tool or protocol expects the standard comma-separated representation. It reverses the DN fields, escapes relevant characters and uses short names. A representative result is:

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject -nameopt RFC2253
subject=CN=example.test,O=Example Org,C=GB

Do not parse the ordinary oneline display as if it were a stable data format. It is intended to be readable, and its spacing and escaping choices are different. For a script, decide what format the receiving system requires, then test with names containing commas, non-ASCII characters or escaped values before relying on it.

5. Inspect unusual names without guessing

Individual flags let you investigate a name when a preset hides a detail. sname uses short attribute names, lname uses long names, and oid prints numerical object identifiers. The last form is useful when OpenSSL does not recognise an attribute or when you are comparing encoded data across systems.

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject \
    -nameopt oid,sep_comma_plus
subject=2.5.4.6=GB,2.5.4.10=Example Org,2.5.4.3=example.test

dump_unknown includes fields whose OIDs OpenSSL does not recognise. dump_nostr and dump_all are diagnostic choices for unusual string or non-character fields. Be cautious with output copied into tickets or logs: escaping makes data safer to interpret, but a DN can still contain identifying information.

6. Keep display choices separate from certificate changes

-nameopt changes how OpenSSL displays a DN. It does not rewrite the certificate, alter its subject, change its issuer or affect trust. Avoid adding certificate-generation options such as -new, -key or -set_subject to a diagnostic command unless you are deliberately creating a new certificate workflow. Those operations can create files or replace output, and are outside this guide.

If you redirect output for a report, choose a new destination first. Shell > truncates an existing file before OpenSSL runs:

$ /usr/bin/openssl x509 -in /path/to/certificate.pem -noout -subject -nameopt multiline \
    > /tmp/subject-name.txt
$ test -s /tmp/subject-name.txt && sed -n '1,6p' /tmp/subject-name.txt

Use a controlled directory for sensitive reports. If the command fails, check the input path and the exact option spelling; the certificate itself has not been changed. Remove a temporary report only when you have confirmed it is no longer needed.

Done means

  • You confirmed which OpenSSL binary and version you are using.
  • You can display a subject or issuer with the default one-line format.
  • You can switch to multiline for human review and RFC2253 for a standards-oriented representation.
  • You know that lname is singular and that unknown options fail rather than silently doing something else.
  • You kept display commands separate from certificate creation or modification, and did not overwrite a useful report.