Ask Steves · Daily notes · VPS, 20% off · AI Profit Lab · SEO · Money Hub

24 September 2026 · One command a day

How do I check a website's SSL certificate from the command line?

This command opens a TLS connection to a website and prints the certificate chain the server sends back, along with whether your machine trusts it. You reach for it when a browser shows a padlock warning, when a renewal has just run, or when you want to prove a certificate problem is on the server rather than in someone's browser. It works from any Linux machine, including the VPS itself.

The command

openssl s_client -connect example.com:443 -servername example.com

openssl is the OpenSSL toolkit, installed by default on Ubuntu 24.04. s_client is its generic TLS client. -connect example.com:443 is the host and port to reach, and 443 is the standard HTTPS port. -servername example.com sets the Server Name Indication (SNI) field, which tells the server which site's certificate you want. On a server that hosts many sites on one IP address, that field decides which certificate comes back. When the handshake finishes the command waits for input. Press Ctrl+C to leave.

What you will see

CONNECTED(00000003)
depth=2 C = GB, O = Example Root CA, CN = Example Root
verify return:1
depth=1 C = GB, O = Example CA, CN = Example Intermediate
verify return:1
depth=0 CN = example.com
verify return:1
---
Certificate chain
 0 s:CN = example.com
   i:C = GB, O = Example CA, CN = Example Intermediate
   v:NotBefore: Aug 12 09:14:33 2026 GMT; NotAfter: Nov 10 09:14:32 2026 GMT
 1 s:C = GB, O = Example CA, CN = Example Intermediate
   i:C = GB, O = Example Root CA, CN = Example Root
   v:NotBefore: Mar 13 00:00:00 2024 GMT; NotAfter: Mar 12 23:59:59 2027 GMT
---
Server certificate
subject=CN = example.com
issuer=C = GB, O = Example CA, CN = Example Intermediate
---
SSL handshake has read 3512 bytes and written 393 bytes
Verification: OK
---
New, TLSv1.3, Cipher is TLS_AES_256_GCM_SHA384
Verify return code: 0 (ok)

The output is trimmed here. The real thing also prints the certificate itself as a block of base64. The depth lines show OpenSSL walking the chain from the root down to your site, and verify return:1 on each step means it passed. The Certificate chain section lists what the server actually sent. Entry 0 is your certificate, entry 1 is the intermediate that signed it, and the v: line gives the validity dates. The two lines that matter most are near the bottom. Verification: OK and Verify return code: 0 (ok) mean a client with a normal trust store will accept this site. Anything else is worth chasing.

When to use it

Watch out for

Leaving off -servername is the classic mistake. Without it the server does not know which site you want, so it sends the default certificate for that IP address, and you end up debugging a mismatch that real browsers never see. The other surprise is that the command does not exit on its own. If you put it in a script or a pipe, feed it empty input with < /dev/null so it closes the connection after the handshake instead of hanging.

Questions people ask

How do I get just the pass or fail line?

Pipe it through grep: openssl s_client -connect example.com:443 -servername example.com < /dev/null 2>/dev/null | grep -A2 "Verify". That prints the verify return code and little else, which suits a quick check script.

What does "unable to get local issuer certificate" mean?

The server sent your certificate but not the intermediate that signed it, so the chain cannot be completed. In nginx, point ssl_certificate at fullchain.pem rather than cert.pem, then test the config and reload.

Checking the chain from the shell, on the machine that serves it, is the kind of thing you can only do on a server you control. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.

Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.

GET A VPS, 20% OFF →

Affiliate link.

More daily notes: How do I query a specific DNS server with dig? · How do I check what a domain resolves to from the command line? · How do I measure a website's response time from the command line?