Home / Alt manpages / openssl-storeutl(1ssl)

  • openssl-storeutl(1ssl)
  • OpenSSL command
  • linux

Inspect Certificates and Keys Safely with openssl storeutl

You will use openssl storeutl to read objects from a file URI, inspect a certificate, and examine an encrypted PKCS#12 bundle without printing private material. Allow about ten minutes if the files already exist. The examples use ordinary user permissions. Elevation is not normally needed unless the input or destination is deliberately protected.

1. Check the installed command

This guide is written for the OpenSSL 3.6.1 installation on this machine. The installed manual page is dated 18 August 2026, and the command reports OpenSSL 3.6.1. The command was added in OpenSSL 1.1.1, but flags and provider behaviour can vary between releases, so check the local help when moving a script to another host.

$ openssl version
OpenSSL 3.6.1 27 Jan 2026 (Library: OpenSSL 3.6.1 27 Jan 2026)
$ openssl storeutl -help
Usage: storeutl [options] uri

The final argument is a URI. For local files, use a file: URI, such as file:/srv/tls/issuer.pem. Put every option before that URI. The local manual specifically warns that options after the URI are ignored, which can make a command appear to work while silently skipping a filter.

Checkpoint: identify the input

Keep the original file and confirm that the account running the command can read it. Do not use sudo as a troubleshooting reflex. First check the path and permissions:

$ ls -l /path/to/certificate-or-store
$ test -r /path/to/certificate-or-store && echo readable

A URI is not a certificate format declaration. The store loader determines what it can fetch from the URI. A PEM certificate, a private key, a certificate revocation list, and a PKCS#12 file can produce different objects.

2. Inspect a certificate without emitting PEM

Use -text for a human-readable representation and -noout to suppress the PEM object. This is a useful first pass because it avoids filling a terminal or a log with encoded certificate data.

$ openssl storeutl -noout -text \
    file:/path/to/certificate.pem

For a certificate, expect a numbered object followed by fields such as Issuer, Subject, validity dates, the public-key algorithm and extensions. The command also reports a total, for example Total found: 1. The exact serial number and dates depend on your certificate.

-noout is an output choice, not a verification operation. It does not prove that a certificate is trusted, valid for a hostname, unexpired or correctly chained. Use the separate OpenSSL verification commands when you need those checks.

3. Read an encrypted PKCS#12 bundle

A PKCS#12 file may contain several objects and may require a password. Pass the password through -passin, before the URI. This demonstrative form puts the password in the command line, so use it only with a throwaway test password and do not copy it into a shared shell history or process listing:

$ openssl storeutl -passin pass:REPLACE_WITH_TEST_PASSWORD \
    -noout file:/path/to/bundle.p12

For a bundle containing one private key and one certificate, a successful run on the installed command reports two objects similar to this:

0: Pkey
1: Certificate
Total found: 2

For a real secret, use a password source supported by your local openssl-passphrase-options(1) documentation rather than exposing the value in a command. If you omit -passin, OpenSSL may prompt interactively. A prompt is expected for an encrypted input, not evidence that the file is corrupt.

4. Select only the object types you need

The -certs, -keys and -crls options select certificates, keys or CRLs from the URI. Selection is especially useful before using -out, because it limits what is emitted. A bundle can still return a set of names or URIs when the URI itself represents names; those names are always returned.

$ openssl storeutl -passin pass:REPLACE_WITH_TEST_PASSWORD \
    -certs -noout -text file:/path/to/bundle.p12

Use -keys only when you genuinely need to inspect a key object. Avoid -text in logs for private keys: a text dump can disclose the key parameters. Keep inspection output on a terminal with appropriate access controls, or use -noout when you only need to count or fetch objects.

5. Extract PEM deliberately

Without -noout, the command writes PEM data to standard output by default. The -out option sends that output to a file instead. This changes state on disk, so choose a new destination and check it before replacing anything useful.

$ openssl storeutl -passin pass:REPLACE_WITH_TEST_PASSWORD \
    -certs -out /path/to/new-certificates.pem \
    file:/path/to/bundle.p12
$ openssl storeutl -noout -text file:/path/to/new-certificates.pem

Do not redirect a private-key selection to a broadly readable file. Check the resulting permissions and correct them using your normal account or secret-management procedure. If the output is wrong, stop and retain the original bundle. Remove only the newly created file after you have confirmed it is not needed; there is no undo for an intentional deletion.

6. Search a store by identity

For stores that expose searchable objects, use -subject, -issuer with -serial, -alias or -fingerprint. A subject uses slash-separated attributes. The issuer and serial options must be supplied together. Serial numbers can be decimal or hexadecimal when prefixed with 0x.

$ openssl storeutl -subject '/CN=storeutl.example/O=Guide Test' \
    -noout file:/path/to/certificate-or-store
$ openssl storeutl -issuer '/CN=Example Issuer' -serial 0x1234 \
    -noout file:/path/to/certificate-or-store

Quote the subject argument. Spaces are retained, and a slash or other special character in a distinguished name may need a backslash escape. A search that finds nothing is a useful result to report separately from a loader error. Check the command's exit status in a script rather than matching terminal wording.

7. Diagnose the common traps

If the command says it cannot open the URI, check the exact file: spelling, the path, read permission and whether the format is supported by the active providers. If an encrypted bundle prompts for a password, rerun with the correct -passin source. Do not put -text, -certs or -noout after the URI: the local manual says those options are ignored there.

If a command prints PEM when you expected only a report, add -noout. If it prints no PEM when you wanted an extracted object, remove -noout and use -out or a carefully chosen redirection. If a bundle contains several objects, add a type filter and inspect the result before saving it.

The -engine option is deprecated in OpenSSL 3.0. Prefer the provider options when your deployment requires a particular provider, and check the local openssl(1), provider and property documentation before changing provider selection. Loading a provider can change which algorithms or store loaders are available; it is not a harmless cosmetic setting.

Done means

  • The local OpenSSL version and storeutl -help output were checked.
  • The input was addressed as a URI and all options were placed before it.
  • -noout -text was used for inspection without dumping PEM unnecessarily.
  • Encrypted input used an appropriate -passin source, without publishing a real password.
  • Certificate, key and CRL selection was explicit before any output file was created.
  • Any extracted file was written to a new, access-controlled path and verified before further use.