Inspect and convert SSL certificates with openssl
VKB-1109How-to
- 📦 Applies to
- XCP-ngXen Orchestra
- 🗓️ Created
- 2024-03-26
- 🔄 Updated
- 2026-08-12
- 🏷️ Tags
Environment
Any host with openssl. Useful when a customer reports a certificate error
against XOA, a host, or a backup remote.
Procedure
Show the certificates a server presents. Everything after the first one can be concatenated into a CA chain file:
# openssl s_client -connect $address:$port -showcerts </dev/null
Verify a chain file against the server:
# openssl s_client -connect $address:$port -verifyCAfile chain.pem </dev/null
Display a certificate in readable form, which is how you check the subject, the SANs and the expiry:
# openssl x509 -in cert.pem -noout -text
Convert a certificate from binary DER to text PEM:
# openssl x509 -in cert.der -outform pem -out cert.pem
Verification
A successful verify ends with Verify return code: 0 (ok). Anything else
names the reason, most often an incomplete chain or a hostname that does not
match a SAN.
Was this page helpful?