Inspect and Check X.509 Certificates with openssl x509
You will use openssl x509 to inspect a certificate, extract the fields that matter during a TLS incident, check a hostname and expiry window, and convert between PEM and DER without touching the original. Allow about fifteen minutes. You need OpenSSL and a readable certificate file. The examples are ordinary, unprivileged commands unless the certificate is in a protected directory.
The route
Jump straight to the step you need, or tick off Done means at the end.
- 1. Confirm the command and input format
- 2. Get the useful summary first
- 3. Inspect extensions and identity fields
- 4. Check a hostname, email address or IP address
- 5. Check the expiry window in automation
- 6. Compare fingerprints and public keys
- 7. Convert PEM and DER without overwriting the source
- Common traps
This guide follows the installed OpenSSL command, version 3.6.1. The local manual page is labelled OpenSSL 3.0.13, so the version printed by the executable is the better description of what will run here. Option details can differ between releases.
1. Confirm the command and input format
Start by checking which executable your shell will call, then ask it for its version:
$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version
OpenSSL 3.6.1 27 Jan 2026
OpenSSL normally tries PEM input first. PEM is the text form with lines such as -----BEGIN CERTIFICATE-----; DER is the binary form. Keep the input path explicit when you are checking a file supplied by another system:
$ test -r /path/to/certificate.pem && echo 'certificate is readable'
certificate is readable
Checkpoint: the file must be the certificate you intend to inspect. A private key is a different object. Do not paste private-key contents into a terminal transcript or upload them to a ticket.
2. Get the useful summary first
Use separate printing options with -noout. That suppresses the normal certificate output while retaining the requested fields:
$ openssl x509 -in /path/to/certificate.pem -noout \
-subject -issuer -serial -dates
subject=CN=example.test
issuer=CN=Example Test CA
serial=1234
notBefore=Sep 25 09:11:18 2026 GMT
notAfter=Oct 25 09:11:18 2026 GMT
The exact names, serial number and dates will be different for your certificate. subject identifies the certificate holder, while issuer identifies the signer. The validity dates are in GMT. They do not by themselves prove that a chain is trusted, that a key is usable, or that a service is presenting this certificate.
For a complete human-readable dump, replace the field options with -text:
$ openssl x509 -in /path/to/certificate.pem -noout -text
Certificate:
Data:
Version: 3 (0x2)
Serial Number: ...
Signature Algorithm: ...
Issuer: ...
Validity
Subject: ...
Output is long because it includes the public key, signature information, extensions and any trust data. Redirect it to a temporary file if you need to search it, but avoid writing sensitive certificate material into a shared location.
3. Inspect extensions and identity fields
For hostname work, start with the Subject Alternative Name extension. It is usually more useful than reading the common name:
$ openssl x509 -in /path/to/certificate.pem -noout -ext subjectAltName
X509v3 Subject Alternative Name:
DNS:example.test, email:[email protected]
The -ext argument accepts a comma-separated list, so a focused check can include more than one extension:
$ openssl x509 -in /path/to/certificate.pem -noout \
-ext subjectAltName,authorityInfoAccess
If you need addresses embedded in the certificate, -email prints unique email addresses found in the subject and Subject Alternative Name extension. -ocsp_uri prints OCSP responder addresses when present. These are inspection results, not commands to contact those services.
4. Check a hostname, email address or IP address
Ask x509 to perform the matching check instead of comparing names by eye:
$ openssl x509 -in /path/to/certificate.pem -noout -checkhost example.test
Hostname example.test does match certificate
$ printf 'status=%s\n' "$?"
status=0
A mismatch is a failed check and returns status 1 on the installed command:
$ openssl x509 -in /path/to/certificate.pem -noout -checkhost wrong.example
Hostname wrong.example does NOT match certificate
$ printf 'status=%s\n' "$?"
status=1
Use -checkemail ADDRESS for an email identity or -checkip ADDRESS for an IP address. Capture the status immediately if a script depends on it. This checks the identity against the certificate, not whether a remote server is currently serving it. For that second question, inspect the certificate obtained from the live connection separately.
5. Check the expiry window in automation
-checkend takes seconds from now. It returns zero when the certificate will not expire within that window, and non-zero when it will:
$ openssl x509 -in /path/to/certificate.pem -noout -checkend 2592000
Certificate will not expire
$ printf 'status=%s\n' "$?"
status=0
The value 2592000 is 30 days. Do not parse the sentence in a monitoring script. Use the exit status and keep a failing result visible:
if openssl x509 -in "$CERT" -noout -checkend 2592000; then
printf '%s\n' 'certificate has more than 30 days remaining'
else
status=$?
printf 'certificate expires within 30 days, or the check failed (status %s)\n' "$status" >&2
exit "$status"
fi
Check the dates as well when investigating an alert. A certificate can be not yet valid, expired already, or valid for too little time even when a hostname matches.
6. Compare fingerprints and public keys
A fingerprint is a digest of the DER-encoded certificate. Ask for the digest algorithm explicitly when people need to compare results:
$ openssl x509 -in /path/to/certificate.pem -noout -fingerprint -sha256
sha256 Fingerprint=AA:BB:CC:...:YY:ZZ
The local manual says the default for -fingerprint is SHA-1 unless a digest is selected. Use -sha256 in new notes and scripts so the algorithm is not left to a default. The fingerprint identifies the whole certificate, not just its public key.
To inspect the public key block itself, use -pubkey:
$ openssl x509 -in /path/to/certificate.pem -noout -pubkey
-----BEGIN PUBLIC KEY-----
...
-----END PUBLIC KEY-----
Never use a matching subject or fingerprint as proof that a private key is safe. Treat any command involving -key, -CAkey, signing, trust settings or output replacement as security-sensitive. Test on copies and protect the private key with its normal file permissions.
7. Convert PEM and DER without overwriting the source
PEM is the default output format. To produce a DER copy, choose a new destination and set both formats explicitly:
$ openssl x509 -in /path/to/certificate.pem -inform PEM \
-out /path/to/certificate.der -outform DER
$ openssl x509 -in /path/to/certificate.der -inform DER -noout -subject
subject=CN=example.test
The second command is the checkpoint that proves the new file can be read as DER. The conversion does not extend validity, repair a chain or change the certificate identity. If a destination already exists, stop before the first command and choose another name or make an explicit backup. Replacing a certificate used by a service can cause an outage; replacement and service reload belong in a planned maintenance procedure with a rollback copy.
Common traps
-nooutis not a verification mode. It only suppresses normal certificate output.-checkhostchecks a certificate identity, not a remote endpoint and not a complete trust chain.-textis useful for investigation but too noisy for stable scripts. Prefer named fields and exit statuses.-inform DERchanges how input is parsed; it does not convert a file by itself.sudois not normally needed. Use elevated access only when the certificate path is deliberately protected, and do not grant write access just to inspect it.
Done means
- You confirmed the OpenSSL executable and version.
- You recorded subject, issuer, serial and validity dates with
-noout. - You checked the relevant extension and identity, using the exit status in scripts.
- You used an explicit digest for fingerprint comparisons and an explicit format for conversions.
- You kept the source certificate and any private key protected, with a rollback copy before any planned replacement.