openssl.md (9469B)
1 --- 2 title: "OpenSSL" 3 description: "OpenSSL: keys, CSRs, certs, x509 inspection, PEM/DER conversion, s_client and encryption." 4 category: cryptography 5 tags: [cryptography, tls, certificates] 6 tools: [OpenSSL] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "repo:Misc/openssl-cheatsheet.pdf" 10 --- 11 12 # OpenSSL 13 14 Full-featured toolkit for SSL/TLS and general-purpose cryptography. In pentesting it is essential for certificate manipulation, TLS reconnaissance, and cryptographic operations. 15 16 > **Note —** Pre-installed on most Linux distros. Invaluable for extracting credentials from certificates, testing SSL configs, and manipulating cryptographic data during engagements. 17 18 ```bash 19 # Install (Debian/Kali) 20 sudo apt update && sudo apt install openssl 21 22 # Version + build info 23 openssl version -a 24 ``` 25 26 --- 27 28 ## PKCS12 / PFX Operations 29 30 PKCS#12 (`.pfx`, `.p12`) files bundle certificates and private keys. Frequently found during pentests — often carrying auth credentials. 31 32 > **Warning —** PFX files from Windows environments often contain domain authentication certificates. Extracting these can give direct access via Evil-WinRM or SSH. 33 34 ```bash 35 # Extract private key (prompts for password) 36 openssl pkcs12 -in cert.pfx -nocerts -out key.pem 37 38 # Extract private key unencrypted (-nodes = no DES) 39 openssl pkcs12 -in cert.pfx -nocerts -out key.pem -nodes 40 41 # Extract certificate only (no keys) 42 openssl pkcs12 -in cert.pfx -nokeys -out cert.pem 43 44 # Extract full certificate chain 45 openssl pkcs12 -in cert.pfx -nokeys -chain -out fullchain.pem 46 47 # Extract everything to a single file 48 openssl pkcs12 -in cert.pfx -out all.pem -nodes 49 50 # Extract CA certificates 51 openssl pkcs12 -in cert.pfx -cacerts -out ca.pem -nokeys 52 ``` 53 54 > **Tip —** Common PFX passwords to try: empty (just press Enter), `password`, `changeit`, `123456`, `mimikatz`. 55 56 ```bash 57 # Create PFX from separate key + cert 58 openssl pkcs12 -export -out certificate.pfx \ 59 -inkey private.key -in certificate.crt 60 61 # Include CA chain 62 openssl pkcs12 -export -out certificate.pfx \ 63 -inkey private.key -in certificate.crt \ 64 -certfile ca-chain.crt 65 ``` 66 67 --- 68 69 ## Certificate Operations 70 71 ```bash 72 # View certificate in human-readable form 73 openssl x509 -in cert.pem -text -noout 74 75 # View specific fields 76 openssl x509 -in cert.pem -subject -noout 77 openssl x509 -in cert.pem -issuer -noout 78 openssl x509 -in cert.pem -dates -noout 79 openssl x509 -in cert.pem -serial -noout 80 81 # View Subject Alternative Names (SANs) 82 openssl x509 -in cert.pem -text -noout | grep -A1 "Subject Alternative Name" 83 ``` 84 85 ### Convert formats 86 87 ```bash 88 # PEM <-> DER 89 openssl x509 -in cert.pem -outform DER -out cert.der 90 openssl x509 -in cert.der -inform DER -out cert.pem 91 92 # PEM -> PKCS7 93 openssl crl2pkcs7 -nocrl -certfile cert.pem -out cert.p7b 94 95 # PKCS7 -> PEM 96 openssl pkcs7 -in cert.p7b -print_certs -out cert.pem 97 ``` 98 99 ### Verify 100 101 ```bash 102 # Verify certificate against CA 103 openssl verify -CAfile ca.pem cert.pem 104 105 # Verify with intermediate chain 106 openssl verify -CAfile ca.pem -untrusted intermediate.pem cert.pem 107 108 # Check whether a key matches a certificate (MD5 of moduli must match) 109 openssl x509 -noout -modulus -in cert.pem | openssl md5 110 openssl rsa -noout -modulus -in key.pem | openssl md5 111 ``` 112 113 --- 114 115 ## Key Operations 116 117 ```bash 118 # RSA private key (2048-bit) 119 openssl genrsa -out private.key 2048 120 121 # RSA key with passphrase (4096-bit) 122 openssl genrsa -aes256 -out private.key 4096 123 124 # EC private key 125 openssl ecparam -genkey -name secp384r1 -out ec_private.key 126 127 # ED25519 key 128 openssl genpkey -algorithm ED25519 -out ed25519.key 129 130 # View RSA private key 131 openssl rsa -in private.key -text -noout 132 133 # Extract public key 134 openssl rsa -in private.key -pubout -out public.key 135 136 # Check key validity 137 openssl rsa -in private.key -check 138 139 # Remove passphrase from key 140 openssl rsa -in encrypted.key -out decrypted.key 141 openssl ec -in encrypted_ec.key -out decrypted_ec.key 142 ``` 143 144 > **Warning —** Removing passphrases creates unprotected keys. Handle with care and delete when no longer needed. 145 146 --- 147 148 ## SSL/TLS Testing 149 150 ```bash 151 # Basic SSL connection 152 openssl s_client -connect host:443 153 154 # Show full certificate chain 155 openssl s_client -connect host:443 -showcerts 156 157 # Specify SNI 158 openssl s_client -connect host:443 -servername hostname 159 160 # Force a TLS version 161 openssl s_client -connect host:443 -tls1_2 162 openssl s_client -connect host:443 -tls1_3 163 ``` 164 165 ### Certificate reconnaissance 166 167 ```bash 168 # Extract server certificate details 169 echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -text -noout 170 171 # Expiration dates 172 echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -noout -dates 173 174 # Extract SANs (find additional hostnames) 175 echo | openssl s_client -connect host:443 2>/dev/null | \ 176 openssl x509 -noout -text | grep -A1 "Subject Alternative" 177 178 # Save the server certificate to disk 179 echo | openssl s_client -connect host:443 2>/dev/null | \ 180 sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > server.crt 181 ``` 182 183 > **Tip —** SANs often reveal internal hostnames, dev servers, and subdomains not publicly listed. 184 185 ### Config / cipher testing 186 187 ```bash 188 # Test a specific cipher 189 openssl s_client -connect host:443 -cipher 'ECDHE-RSA-AES256-SHA' 190 191 # List supported ciphers 192 openssl ciphers -v 'ALL:COMPLEMENTOFALL' 193 194 # Test SSLv3 (POODLE) 195 openssl s_client -connect host:443 -ssl3 196 197 # Probe weak ciphers 198 openssl s_client -connect host:443 -cipher 'NULL,EXPORT,LOW,DES' 199 ``` 200 201 ### STARTTLS services 202 203 ```bash 204 openssl s_client -connect mail.host:25 -starttls smtp 205 openssl s_client -connect mail.host:143 -starttls imap 206 openssl s_client -connect mail.host:110 -starttls pop3 207 openssl s_client -connect ftp.host:21 -starttls ftp 208 openssl s_client -connect ldap.host:389 -starttls ldap 209 openssl s_client -connect xmpp.host:5222 -starttls xmpp 210 ``` 211 212 --- 213 214 ## Encryption & Decryption 215 216 ```bash 217 # Symmetric AES-256-CBC (use PBKDF2 for real work) 218 openssl enc -aes-256-cbc -salt -pbkdf2 -in file.txt -out file.enc 219 openssl enc -aes-256-cbc -d -pbkdf2 -in file.enc -out file.txt 220 221 # Base64-armored output 222 openssl enc -aes-256-cbc -a -salt -pbkdf2 -in file.txt -out file.enc 223 224 # Asymmetric (pkeyutl preferred on modern OpenSSL) 225 openssl pkeyutl -encrypt -pubin -inkey public.key -in plaintext.txt -out encrypted.bin 226 openssl pkeyutl -decrypt -inkey private.key -in encrypted.bin -out plaintext.txt 227 ``` 228 229 --- 230 231 ## Hashing 232 233 ```bash 234 openssl dgst -md5 file.txt 235 openssl dgst -sha1 file.txt 236 openssl dgst -sha256 file.txt 237 openssl dgst -sha512 file.txt 238 239 # Hash a string 240 echo -n "password" | openssl dgst -sha256 241 242 # HMAC (keyed) 243 openssl dgst -sha256 -hmac "secret_key" file.txt 244 echo -n "message" | openssl dgst -sha256 -hmac "key" 245 ``` 246 247 --- 248 249 ## Base64 250 251 ```bash 252 openssl base64 -in file.bin -out file.b64 # encode 253 openssl base64 -d -in file.b64 -out file.bin # decode 254 echo -n "text" | openssl base64 255 openssl base64 -A -in file.bin # no line breaks 256 ``` 257 258 --- 259 260 ## Passwords & Random 261 262 ```bash 263 # Unix crypt hashes 264 openssl passwd -1 "password" # MD5 265 openssl passwd -5 "password" # SHA-256 266 openssl passwd -6 "password" # SHA-512 267 openssl passwd -6 -salt "customsalt" "password" 268 openssl passwd -apr1 "password" # Apache htpasswd 269 270 # Random data 271 openssl rand -hex 32 272 openssl rand -base64 32 273 openssl rand -out random.bin 256 274 ``` 275 276 > **Tip —** `openssl passwd` output can be injected into `/etc/passwd` or `/etc/shadow` during privilege escalation when you can write those files. 277 278 --- 279 280 ## CSR & Self-Signed Certificates 281 282 ```bash 283 # CSR with a fresh key 284 openssl req -new -newkey rsa:2048 -nodes -keyout private.key -out request.csr 285 286 # CSR from an existing key 287 openssl req -new -key private.key -out request.csr 288 289 # Inspect / verify a CSR 290 openssl req -in request.csr -text -noout 291 openssl req -in request.csr -verify 292 293 # Self-signed certificate (1 year) 294 openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes 295 296 # One-liner with subject 297 openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes \ 298 -subj "/CN=localhost/O=Test/C=US" 299 ``` 300 301 --- 302 303 ## HTB / Engagement Scenarios 304 305 ```bash 306 # Windows cert auth via Evil-WinRM 307 openssl pkcs12 -in user_auth.pfx -nocerts -out user.key -nodes 308 openssl pkcs12 -in user_auth.pfx -nokeys -out user.crt 309 evil-winrm -i target.htb -c user.crt -k user.key -S 310 311 # SSH key from a PFX 312 openssl pkcs12 -in ssh_cert.pfx -nocerts -out id_rsa -nodes 313 chmod 600 id_rsa 314 ssh -i id_rsa user@target 315 316 # ADCS recon from a certificate 317 openssl x509 -in cert.pem -text -noout | grep -A5 "Issuer" 318 openssl x509 -in cert.pem -text -noout | grep -A10 "Extensions" 319 openssl x509 -in cert.pem -text -noout | grep -i "principal" # UPN 320 ``` 321 322 --- 323 324 ## Common Options Reference 325 326 | Option | Description | 327 |---|---| 328 | `-in <file>` | Input file | 329 | `-out <file>` | Output file | 330 | `-text` | Human-readable text output | 331 | `-noout` | Suppress encoded output | 332 | `-nodes` | No DES (unencrypted key) | 333 | `-nocerts` | Don't output certificates | 334 | `-nokeys` | Don't output private keys | 335 | `-passin pass:<pwd>` | Input password | 336 | `-passout pass:<pwd>` | Output password | 337 | `-inform DER/PEM` | Input format | 338 | `-outform DER/PEM` | Output format | 339 | `-CAfile <file>` | CA certificate file | 340 | `-verify` | Verify signature / certificate | 341 342 --- 343 344 ## Resources 345 346 * Official docs: <https://www.openssl.org/docs/> 347 * Man pages: `man openssl`, `man openssl-x509` 348 349 > For **authorized security testing only.** Extracting credentials from certificates or testing SSL configurations without permission is illegal.