Linux openssl Command

Complete Linux Commands


OpenSSL is a powerful open-source cryptographic toolkit that provides various encryption algorithms, certificate management functions, and SSL/TLS protocol implementations. It is the de facto standard tool for handling encryption tasks in Linux systems.

The main functions of OpenSSL include:

  • Create and manage SSL certificates
  • Encrypt/decrypt files
  • Generate key pairs
  • Test SSL connections
  • Calculate hash values
  • Digital signature verification

Basic Syntax

The basic syntax format of the openssl command is:

openssl command [command_options] [command_args]

Where:

  • commandcommand: The OpenSSL subcommand to execute (e.g., genrsa, req, x509, etc.)
  • command_optionsoptions: Options for the subcommand
  • command_argsarguments: Arguments for the subcommand

Common Subcommands and Examples

1. Generate RSA Key Pair

Generate a 2048-bit RSA private key:

openssl genrsa -out private.key 2048

Extract the public key from the private key:

openssl rsa -in private.key -pubout -out public.key

Parameter explanation:

  • -out-out: Specify the output file
  • 2048bits: Key length (bits)
  • -pubout-pubout: Output the public key

2. Create Self-Signed Certificate

Generate a CSR (Certificate Signing Request):

openssl req -new -key private.key -out cert.csr

Generate a self-signed certificate (valid for 365 days):

openssl req -x509 -new -key private.key -days 365 -out cert.crt

Parameter explanation:

  • -new-new: Create a new request
  • -key-key: Specify the private key file
  • -days-days: Certificate validity period (days)
  • -x509-x509: Output X.509 format certificate

3. File Encryption and Decryption

Encrypt a file using AES-256-CBC:

openssl enc -aes-256-cbc -salt -in plaintext.txt -out encrypted.enc

Decrypt the file:

openssl enc -d -aes-256-cbc -in encrypted.enc -out decrypted.txt

Parameter explanation:

  • -aes-256-cbc-aes-256-cbc: Use AES-256-CBC algorithm
  • -salt-salt: Add a random salt to enhance security
  • -in-in: Input file
  • -out-out: Output file
  • -d-d: Decryption mode

4. Calculate File Hash Value

Calculate SHA-256 hash:

openssl dgst -sha256 filename.txt

Calculate MD5 hash:

openssl dgst -md5 filename.txt

5. Test SSL Connection

Test the SSL certificate of a remote server:

openssl s_client -connect example.com:443 -showcerts

Parameter explanation:

  • -connect-connect: Specify the host and port
  • -showcerts-showcerts: Display the server certificate chain

Advanced Usage

1. Create PKCS#12 Format Certificate

Package the certificate and private key into a PKCS#12 file:

openssl pkcs12 -export -in cert.crt -inkey private.key -out cert.p12

2. View Certificate Information

View detailed certificate information:

openssl x509 -in cert.crt -text -noout

3. Verify Certificate Chain

Verify the integrity of the certificate chain:

openssl verify -CAfile ca.crt cert.crt

Security Considerations

  1. Key protection: The private key file should be set with appropriate permissions (e.g., 600) to avoid leakage.Algorithm selection: Avoid using insecure algorithms (e.g., MD5, SHA1).
  2. Password strength: Use a strong password when encrypting.Certificate validity period: Regularly renew expired certificates.
  3. Random number generation: Ensure the system has enough entropy for cryptographic operations.: Use a strong password when encrypting
  4. Certificate validity period: Periodically update expired certificates
  5. Random number generationEnsure the system has sufficient entropy for cryptographic operations.

Frequently Asked Questions

Q1: How to check the OpenSSL version?

openssl version

Q2: How to generate more secure ECC keys?

openssl ecparam -genkey -name secp384r1 -out ecc.key

Q3: How to convert certificate formats?

Convert from PEM to DER:

openssl x509 -in cert.pem -outform der -out cert.der

Practical Exercises

  1. Generate a 4096-bit RSA key pair
  2. Create a self-signed certificate valid for 2 years
  3. Encrypt a text file and decrypt it using the same password
  4. Check the SSL certificate information of websites you commonly use

By mastering the openssl command, you will be able to handle various encryption and security-related tasks, laying a solid foundation for system security and management work.


Complete Linux Commands

Other Extensions