Home / Alt manpages / openssl-nseq(1ssl)

  • openssl-nseq(1ssl)
  • OpenSSL command
  • linux

Convert PEM Certificates to a Netscape Sequence with openssl nseq

You will package a PEM certificate bundle into the older Netscape certificate sequence format, extract the certificates again, and verify that the round trip preserved the certificate data. Allow about ten minutes. You need the OpenSSL package and a readable PEM file containing one or more certificates. The examples use OpenSSL 3.6.1, installed here on Linux.

A Netscape certificate sequence is a legacy Netscape-specific container. It is not the same thing as PKCS#7, and it is not a new certificate format. Use it only when the receiving system specifically requires it. The command does not need root privileges when you read and write files in a directory you own.

1. Check the installed command

Confirm the executable and package version before relying on option details. These are ordinary, read-only checks:

$ command -v openssl
/usr/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026

The installed manual describes openssl nseq as both a sequence reader and a sequence creator. Ask the command for its local option summary as a second checkpoint:

$ openssl nseq -help
Usage: nseq [options]

Input options:
 -in infile          Input NS Sequence file

Output options:
 -toseq              Output NS Sequence file
 -out outfile        Output file

The exact help text can gain provider-related options in later releases. The workflow below uses the stable input, output and -toseq options.

2. Inspect the certificate input

Choose an existing PEM bundle and check that it contains certificates before converting it. Replace the placeholder path with your file. This does not change the input:

$ INPUT_PEM=/path/to/certs.pem
$ grep -c '^-----BEGIN CERTIFICATE-----$' "$INPUT_PEM"
2
$ openssl x509 -in "$INPUT_PEM" -noout -subject -issuer
subject=CN=service.example
issuer=CN=Example Issuing CA

openssl x509 reads the first certificate in a PEM stream. The count gives you a quick indication that the file contains the expected number of certificate blocks. If the count is zero, stop and locate the correct PEM file. A private key is not needed for this operation, and you should not add one to the bundle just to make the command accept it.

Checkpoint: keep the original input unchanged and choose a new destination such as /path/to/certs.nseq.pem. Do not use the input path as the output path.

3. Create the Netscape certificate sequence

Pass the certificate bundle to -in, add -toseq, and select a new output file with -out:

$ OUTPUT_NSEQ=/path/to/certs.nseq.pem
$ openssl nseq -in "$INPUT_PEM" -toseq -out "$OUTPUT_NSEQ"
$ printf 'exit status: %s\n' "$?"
exit status: 0

With -toseq, the command reverses its normal direction: it reads certificates and writes a Netscape certificate sequence. The output is PEM armoured, so the beginning should look like a certificate block even though the encoded content is a sequence:

$ head -n 1 "$OUTPUT_NSEQ"
-----BEGIN CERTIFICATE-----
$ test -s "$OUTPUT_NSEQ" && echo 'sequence file is non-empty'
sequence file is non-empty

Do not infer the format from the PEM label alone. The useful verification is to read the result back with openssl nseq, as the next step does.

4. Extract certificates from the sequence

Omit -toseq to use the command in its default direction. It reads a Netscape certificate sequence and writes the certificates it contains:

$ EXTRACTED_PEM=/path/to/certs-extracted.pem
$ openssl nseq -in "$OUTPUT_NSEQ" -out "$EXTRACTED_PEM"
$ grep -c '^-----BEGIN CERTIFICATE-----$' "$EXTRACTED_PEM"
2

The output file is ordinary concatenated PEM certificate material. Compare the certificate count with the original input, then inspect the extracted certificates. For a bundle containing more than one certificate, use a certificate-aware tool or split the PEM blocks before checking each subject:

$ openssl x509 -in "$EXTRACTED_PEM" -noout -subject -issuer
subject=CN=service.example
issuer=CN=Example Issuing CA

This command displays the first certificate only. Matching the count and checking the subjects of every certificate is the stronger test when order and contents matter.

5. Use standard input and output when appropriate

The manual defaults to standard input when -in is absent and standard output when -out is absent. That makes a pipeline possible, but it also makes accidental redirection easy to miss. For a deliberate extraction pipeline:

$ openssl nseq -in "$OUTPUT_NSEQ" | openssl x509 -noout -subject
subject=CN=service.example

For creation from a known bundle, this is equivalent to the file-based form:

$ openssl nseq -toseq < "$INPUT_PEM" > "$OUTPUT_NSEQ.new"
$ test -s "$OUTPUT_NSEQ.new" && echo 'new sequence is non-empty'
new sequence is non-empty

Shell redirection truncates its destination before OpenSSL starts. The temporary suffix protects an existing sequence if conversion fails. After checking the new file, replace the old one explicitly:

$ mv -- "$OUTPUT_NSEQ.new" "$OUTPUT_NSEQ"

This replacement is deliberate and can discard the previous output. Keep a backup first if that file is the only copy. If the conversion fails before the move, remove the incomplete .new file and the original output remains untouched.

6. Diagnose the common failures

An error about opening a file usually means the path, permissions or current user are wrong. Check without changing anything:

$ test -r "$INPUT_PEM" && echo 'input is readable'
$ test -w "$(dirname -- "$OUTPUT_NSEQ")" && echo 'output directory is writable'

If OpenSSL reports that the input is not a Netscape sequence, remove -toseq only if you intended to extract an existing sequence. If you are starting with ordinary PEM certificates, keep -toseq. Confusing these directions is the most common error in this command.

A successful exit status confirms that OpenSSL processed the input, not that a remote enrolment system will accept the result. Check the receiving system's required container format before sending it. Netscape certificate sequences are obsolete outside compatibility workflows, so PKCS#7 or another documented format may be the correct alternative.

Done means

  • The installed OpenSSL version and local nseq -help output were checked.
  • The input PEM bundle was readable and its certificate count was recorded.
  • -toseq created a new, non-empty sequence without changing the input.
  • Running without -toseq extracted PEM certificates and preserved the expected count.
  • Any replacement used a temporary output and an explicit move after verification.