OpenSSL Command Builder
Build the OpenSSL command you need for generating keys, creating certificate signing requests, self signing, converting formats and inspecting a live TLS endpoint.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
A tool with a thousand subcommands and no memory aid
OpenSSL does almost everything in certificate and key handling and its command line reflects thirty years of accumulated options. Almost nobody remembers the incantation for adding subject alternative names to a certificate signing request, or the argument order for converting a PEM bundle into PKCS#12, and getting it wrong produces either an error at the wrong layer or, worse, a certificate that is silently missing something a browser requires.
Subject alternative names are mandatory now
Every current browser ignores the common name field entirely and validates only against the subject alternative name extension. A certificate signing request without SANs produces a certificate that fails in Chrome and Firefox regardless of how correct the common name looks. Adding them requires either a configuration file or the addext option in OpenSSL 1.1.1 and later, and this is the single most common reason a hand made certificate does not work.
Inspecting is usually the faster fix
Before regenerating anything, it is worth reading what you already have. The s_client subcommand connects to a live endpoint and prints the certificate chain, the negotiated protocol and cipher, and whether the chain is complete. A missing intermediate certificate is invisible in a browser that happens to have cached it and fails on a fresh client, which is the classic pattern for a site that works for the person who deployed it and nobody else.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Why does my self signed certificate fail in Chrome?
Almost always missing subject alternative names. Browsers stopped honouring the common name field years ago. The certificate must carry a SAN extension listing every hostname it covers, and a certificate with only a CN fails validation outright.
What key type should I generate?
ECDSA P-256 for new work: smaller, faster, and supported everywhere that matters. RSA 2048 remains the safe default for maximum compatibility with old clients and some appliances. RSA below 2048 is rejected by every current CA and browser.
How do I check a certificate matches its private key?
Compare the modulus hash of each: openssl x509 -noout -modulus -in cert.pem | openssl md5 against openssl rsa -noout -modulus -in key.pem | openssl md5. If they differ, the pair does not match, which is a very common deployment error.
What is the difference between PEM, DER and PKCS#12?
PEM is base64 with header lines and is what most Linux software expects. DER is the raw binary form used by Java and Windows tools. PKCS#12 bundles a certificate, its chain and the private key into one password protected file, which is what Windows and many appliances import.
How do I test a chain is complete?
openssl s_client -connect host:443 -showcerts prints every certificate the server sends. If the chain stops before a certificate signed by a trusted root, an intermediate is missing. Browsers sometimes cache intermediates and hide this, which is why it fails only for new visitors.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Choose a task and fill in the details to get the exact OpenSSL command with its options explained.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.