## TLS certificates, keys, CSRs, hashing, random data and encryption

# Generate an RSA private key
openssl genrsa -out server.key 4096

# Generate an EC (P-256) private key
openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:P-256 -out ec.key

# Create a certificate signing request (CSR)
openssl req -new -key server.key -out server.csr -subj "/C=US/O=Example Inc/CN=example.com"

# Self-signed certificate for local development, with SAN
openssl req -x509 -newkey rsa:4096 -nodes -keyout key.pem -out cert.pem -days 365 -subj "/CN=localhost" -addext "subjectAltName=DNS:localhost,IP:127.0.0.1"

# Read a certificate
openssl x509 -in cert.pem -text -noout

# Validity dates
openssl x509 -in cert.pem -noout -dates

# Subject and issuer
openssl x509 -in cert.pem -noout -subject -issuer

# SHA-256 fingerprint
openssl x509 -in cert.pem -noout -fingerprint -sha256

# Does the certificate expire within 30 days?
openssl x509 -in cert.pem -noout -checkend 2592000 && echo "valid 30+ days" || echo "expires soon"

# Read a CSR
openssl req -in server.csr -text -noout

# Does a key match a certificate? (both hashes must be equal)
openssl x509 -in cert.pem -noout -pubkey | openssl sha256
openssl pkey -in server.key -pubout | openssl sha256

# Verify a certificate against a CA bundle
openssl verify -CAfile ca-bundle.pem cert.pem

# Connect to a TLS server and show its certificate
openssl s_client -connect example.com:443 -servername example.com < /dev/null

# Expiry date of a live website's certificate
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -dates

# Full certificate chain sent by a server
openssl s_client -connect example.com:443 -showcerts < /dev/null

# Test if a server supports TLS 1.2
openssl s_client -connect example.com:443 -tls1_2 < /dev/null

# Test a mail server with STARTTLS
openssl s_client -connect mail.example.com:587 -starttls smtp

# Convert PEM to DER
openssl x509 -in cert.pem -outform der -out cert.der

# Convert DER to PEM
openssl x509 -in cert.der -inform der -out cert.pem

# Bundle key and certificates into a .pfx / .p12 file
openssl pkcs12 -export -out bundle.pfx -inkey server.key -in cert.pem -certfile chain.pem

# Extract everything from a .pfx file
openssl pkcs12 -in bundle.pfx -nodes -out all.pem

# Remove the passphrase from a key
openssl pkey -in encrypted.key -out plain.key

# Public key from a private key
openssl pkey -in server.key -pubout -out server.pub

# Random password
openssl rand -base64 32

# Random hex string (tokens, secrets)
openssl rand -hex 16

# SHA-256 checksum of a file
openssl dgst -sha256 ubuntu.iso

# HMAC signature (webhook verification)
echo -n "payload" | openssl dgst -sha256 -hmac "secret-key"

# Encrypt a file with a password
openssl enc -aes-256-cbc -salt -pbkdf2 -in secrets.txt -out secrets.txt.enc

# Decrypt it
openssl enc -d -aes-256-cbc -pbkdf2 -in secrets.txt.enc -out secrets.txt

# Base64 encode / decode
openssl base64 -in image.png -out image.b64
openssl base64 -d -in image.b64 -out image.png

# Sign a file and verify the signature
openssl dgst -sha256 -sign private.key -out release.sig release.tar.gz
openssl dgst -sha256 -verify public.pem -signature release.sig release.tar.gz

# Password hash for /etc/shadow (SHA-512)
openssl passwd -6 "MyPassword"

# List strong cipher suites
openssl ciphers -v 'HIGH:!aNULL:!MD5'

# OpenSSL version and build info
openssl version -a
