Linux openssl Command
OpenSSL is a powerful open-source cryptographic toolkit that provides various encryption algorithms, certificate management functions, and SSL/TLS protocol implementations. It is the de facto standard tool for handling encryption tasks in Linux systems.
The main functions of OpenSSL include:
- Create and manage SSL certificates
- Encrypt/decrypt files
- Generate key pairs
- Test SSL connections
- Calculate hash values
- Digital signature verification
Basic Syntax
The basic syntax format of the openssl command is:
openssl command [command_options] [command_args]
Where:
commandcommand: The OpenSSL subcommand to execute (e.g., genrsa, req, x509, etc.)command_optionsoptions: Options for the subcommandcommand_argsarguments: Arguments for the subcommand
Common Subcommands and Examples
1. Generate RSA Key Pair
Generate a 2048-bit RSA private key:
openssl genrsa -out private.key 2048
Extract the public key from the private key:
openssl rsa -in private.key -pubout -out public.key
Parameter explanation:
-out-out: Specify the output file2048bits: Key length (bits)-pubout-pubout: Output the public key
2. Create Self-Signed Certificate
Generate a CSR (Certificate Signing Request):
openssl req -new -key private.key -out cert.csr
Generate a self-signed certificate (valid for 365 days):
openssl req -x509 -new -key private.key -days 365 -out cert.crt
Parameter explanation:
-new-new: Create a new request-key-key: Specify the private key file-days-days: Certificate validity period (days)-x509-x509: Output X.509 format certificate
3. File Encryption and Decryption
Encrypt a file using AES-256-CBC:
openssl enc -aes-256-cbc -salt -in plaintext.txt -out encrypted.enc
Decrypt the file:
openssl enc -d -aes-256-cbc -in encrypted.enc -out decrypted.txt
Parameter explanation:
-aes-256-cbc-aes-256-cbc: Use AES-256-CBC algorithm-salt-salt: Add a random salt to enhance security-in-in: Input file-out-out: Output file-d-d: Decryption mode
4. Calculate File Hash Value
Calculate SHA-256 hash:
openssl dgst -sha256 filename.txt
Calculate MD5 hash:
openssl dgst -md5 filename.txt
5. Test SSL Connection
Test the SSL certificate of a remote server:
openssl s_client -connect example.com:443 -showcerts
Parameter explanation:
-connect-connect: Specify the host and port-showcerts-showcerts: Display the server certificate chain
Advanced Usage
1. Create PKCS#12 Format Certificate
Package the certificate and private key into a PKCS#12 file:
openssl pkcs12 -export -in cert.crt -inkey private.key -out cert.p12
2. View Certificate Information
View detailed certificate information:
openssl x509 -in cert.crt -text -noout
3. Verify Certificate Chain
Verify the integrity of the certificate chain:
openssl verify -CAfile ca.crt cert.crt
Security Considerations
- Key protection: The private key file should be set with appropriate permissions (e.g., 600) to avoid leakage.Algorithm selection: Avoid using insecure algorithms (e.g., MD5, SHA1).
- Password strength: Use a strong password when encrypting.Certificate validity period: Regularly renew expired certificates.
- Random number generation: Ensure the system has enough entropy for cryptographic operations.: Use a strong password when encrypting
- Certificate validity period: Periodically update expired certificates
- Random number generationEnsure the system has sufficient entropy for cryptographic operations.
Frequently Asked Questions
Q1: How to check the OpenSSL version?
openssl version
Q2: How to generate more secure ECC keys?
openssl ecparam -genkey -name secp384r1 -out ecc.key
Q3: How to convert certificate formats?
Convert from PEM to DER:
openssl x509 -in cert.pem -outform der -out cert.der
Practical Exercises
- Generate a 4096-bit RSA key pair
- Create a self-signed certificate valid for 2 years
- Encrypt a text file and decrypt it using the same password
- Check the SSL certificate information of websites you commonly use
By mastering the openssl command, you will be able to handle various encryption and security-related tasks, laying a solid foundation for system security and management work.
Other Extensions