openssl show certificate chain

Read the SSL Certificate information from a remote server. November 26, … Accueil; Blog de Boris HUISGEN Administrateur Système UNIX / Linux. Then we create Certificate Signature Request for this key; And then we create a self-signed certificate, valid for 10 years, for this key; openssl genrsa -des3 -out ca.key 2048 openssl req -new -key ca.key -out ca.csr openssl x509 -req -days 3650 -in ca.csr -signkey ca.key -out ca.crt. I may show examples of using OpenSSL, but documenting it's use is out of scope for this article. There are a few reasons that your application server might require access to a full certificate chain. In most cases, you will be asked to provide the certificate and the chain in one PEM certificate file. We can use -partial_chain option. Use -showcerts flag to show full certificate chain, and manually save all intermediate certificates to chain.pem file: openssl s_client -showcerts -host -port 443

