Skip to main content

Inspect and convert SSL certificates with openssl

VKB-1109How-to
📦 Applies to
XCP-ngXen Orchestra
🗓️ Created
2024-03-26
🔄 Updated
2026-08-12

Environment​

Any host with openssl. Useful when a customer reports a certificate error against XOA, a host, or a backup remote.

Procedure​

Show the certificates a server presents. Everything after the first one can be concatenated into a CA chain file:

root@dom0
# openssl s_client -connect $address:$port -showcerts </dev/null

Verify a chain file against the server:

root@dom0
# openssl s_client -connect $address:$port -verifyCAfile chain.pem </dev/null

Display a certificate in readable form, which is how you check the subject, the SANs and the expiry:

root@dom0
# openssl x509 -in cert.pem -noout -text

Convert a certificate from binary DER to text PEM:

root@dom0
# openssl x509 -in cert.der -outform pem -out cert.pem

Verification​

A successful verify ends with Verify return code: 0 (ok). Anything else names the reason, most often an incomplete chain or a hostname that does not match a SAN.