daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

openssl.md (9469B)


      1 ---
      2 title: "OpenSSL"
      3 description: "OpenSSL: keys, CSRs, certs, x509 inspection, PEM/DER conversion, s_client and encryption."
      4 category: cryptography
      5 tags: [cryptography, tls, certificates]
      6 tools: [OpenSSL]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "repo:Misc/openssl-cheatsheet.pdf"
     10 ---
     11 
     12 # OpenSSL
     13 
     14 Full-featured toolkit for SSL/TLS and general-purpose cryptography. In pentesting it is essential for certificate manipulation, TLS reconnaissance, and cryptographic operations.
     15 
     16 > **Note —** Pre-installed on most Linux distros. Invaluable for extracting credentials from certificates, testing SSL configs, and manipulating cryptographic data during engagements.
     17 
     18 ```bash
     19 # Install (Debian/Kali)
     20 sudo apt update && sudo apt install openssl
     21 
     22 # Version + build info
     23 openssl version -a
     24 ```
     25 
     26 ---
     27 
     28 ## PKCS12 / PFX Operations
     29 
     30 PKCS#12 (`.pfx`, `.p12`) files bundle certificates and private keys. Frequently found during pentests — often carrying auth credentials.
     31 
     32 > **Warning —** PFX files from Windows environments often contain domain authentication certificates. Extracting these can give direct access via Evil-WinRM or SSH.
     33 
     34 ```bash
     35 # Extract private key (prompts for password)
     36 openssl pkcs12 -in cert.pfx -nocerts -out key.pem
     37 
     38 # Extract private key unencrypted (-nodes = no DES)
     39 openssl pkcs12 -in cert.pfx -nocerts -out key.pem -nodes
     40 
     41 # Extract certificate only (no keys)
     42 openssl pkcs12 -in cert.pfx -nokeys -out cert.pem
     43 
     44 # Extract full certificate chain
     45 openssl pkcs12 -in cert.pfx -nokeys -chain -out fullchain.pem
     46 
     47 # Extract everything to a single file
     48 openssl pkcs12 -in cert.pfx -out all.pem -nodes
     49 
     50 # Extract CA certificates
     51 openssl pkcs12 -in cert.pfx -cacerts -out ca.pem -nokeys
     52 ```
     53 
     54 > **Tip —** Common PFX passwords to try: empty (just press Enter), `password`, `changeit`, `123456`, `mimikatz`.
     55 
     56 ```bash
     57 # Create PFX from separate key + cert
     58 openssl pkcs12 -export -out certificate.pfx \
     59   -inkey private.key -in certificate.crt
     60 
     61 # Include CA chain
     62 openssl pkcs12 -export -out certificate.pfx \
     63   -inkey private.key -in certificate.crt \
     64   -certfile ca-chain.crt
     65 ```
     66 
     67 ---
     68 
     69 ## Certificate Operations
     70 
     71 ```bash
     72 # View certificate in human-readable form
     73 openssl x509 -in cert.pem -text -noout
     74 
     75 # View specific fields
     76 openssl x509 -in cert.pem -subject -noout
     77 openssl x509 -in cert.pem -issuer  -noout
     78 openssl x509 -in cert.pem -dates   -noout
     79 openssl x509 -in cert.pem -serial  -noout
     80 
     81 # View Subject Alternative Names (SANs)
     82 openssl x509 -in cert.pem -text -noout | grep -A1 "Subject Alternative Name"
     83 ```
     84 
     85 ### Convert formats
     86 
     87 ```bash
     88 # PEM <-> DER
     89 openssl x509 -in cert.pem -outform DER -out cert.der
     90 openssl x509 -in cert.der -inform DER  -out cert.pem
     91 
     92 # PEM -> PKCS7
     93 openssl crl2pkcs7 -nocrl -certfile cert.pem -out cert.p7b
     94 
     95 # PKCS7 -> PEM
     96 openssl pkcs7 -in cert.p7b -print_certs -out cert.pem
     97 ```
     98 
     99 ### Verify
    100 
    101 ```bash
    102 # Verify certificate against CA
    103 openssl verify -CAfile ca.pem cert.pem
    104 
    105 # Verify with intermediate chain
    106 openssl verify -CAfile ca.pem -untrusted intermediate.pem cert.pem
    107 
    108 # Check whether a key matches a certificate (MD5 of moduli must match)
    109 openssl x509 -noout -modulus -in cert.pem | openssl md5
    110 openssl rsa  -noout -modulus -in key.pem  | openssl md5
    111 ```
    112 
    113 ---
    114 
    115 ## Key Operations
    116 
    117 ```bash
    118 # RSA private key (2048-bit)
    119 openssl genrsa -out private.key 2048
    120 
    121 # RSA key with passphrase (4096-bit)
    122 openssl genrsa -aes256 -out private.key 4096
    123 
    124 # EC private key
    125 openssl ecparam -genkey -name secp384r1 -out ec_private.key
    126 
    127 # ED25519 key
    128 openssl genpkey -algorithm ED25519 -out ed25519.key
    129 
    130 # View RSA private key
    131 openssl rsa -in private.key -text -noout
    132 
    133 # Extract public key
    134 openssl rsa -in private.key -pubout -out public.key
    135 
    136 # Check key validity
    137 openssl rsa -in private.key -check
    138 
    139 # Remove passphrase from key
    140 openssl rsa -in encrypted.key -out decrypted.key
    141 openssl ec  -in encrypted_ec.key -out decrypted_ec.key
    142 ```
    143 
    144 > **Warning —** Removing passphrases creates unprotected keys. Handle with care and delete when no longer needed.
    145 
    146 ---
    147 
    148 ## SSL/TLS Testing
    149 
    150 ```bash
    151 # Basic SSL connection
    152 openssl s_client -connect host:443
    153 
    154 # Show full certificate chain
    155 openssl s_client -connect host:443 -showcerts
    156 
    157 # Specify SNI
    158 openssl s_client -connect host:443 -servername hostname
    159 
    160 # Force a TLS version
    161 openssl s_client -connect host:443 -tls1_2
    162 openssl s_client -connect host:443 -tls1_3
    163 ```
    164 
    165 ### Certificate reconnaissance
    166 
    167 ```bash
    168 # Extract server certificate details
    169 echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -text -noout
    170 
    171 # Expiration dates
    172 echo | openssl s_client -connect host:443 2>/dev/null | openssl x509 -noout -dates
    173 
    174 # Extract SANs (find additional hostnames)
    175 echo | openssl s_client -connect host:443 2>/dev/null | \
    176   openssl x509 -noout -text | grep -A1 "Subject Alternative"
    177 
    178 # Save the server certificate to disk
    179 echo | openssl s_client -connect host:443 2>/dev/null | \
    180   sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > server.crt
    181 ```
    182 
    183 > **Tip —** SANs often reveal internal hostnames, dev servers, and subdomains not publicly listed.
    184 
    185 ### Config / cipher testing
    186 
    187 ```bash
    188 # Test a specific cipher
    189 openssl s_client -connect host:443 -cipher 'ECDHE-RSA-AES256-SHA'
    190 
    191 # List supported ciphers
    192 openssl ciphers -v 'ALL:COMPLEMENTOFALL'
    193 
    194 # Test SSLv3 (POODLE)
    195 openssl s_client -connect host:443 -ssl3
    196 
    197 # Probe weak ciphers
    198 openssl s_client -connect host:443 -cipher 'NULL,EXPORT,LOW,DES'
    199 ```
    200 
    201 ### STARTTLS services
    202 
    203 ```bash
    204 openssl s_client -connect mail.host:25   -starttls smtp
    205 openssl s_client -connect mail.host:143  -starttls imap
    206 openssl s_client -connect mail.host:110  -starttls pop3
    207 openssl s_client -connect ftp.host:21    -starttls ftp
    208 openssl s_client -connect ldap.host:389  -starttls ldap
    209 openssl s_client -connect xmpp.host:5222 -starttls xmpp
    210 ```
    211 
    212 ---
    213 
    214 ## Encryption & Decryption
    215 
    216 ```bash
    217 # Symmetric AES-256-CBC (use PBKDF2 for real work)
    218 openssl enc -aes-256-cbc -salt -pbkdf2 -in file.txt  -out file.enc
    219 openssl enc -aes-256-cbc -d    -pbkdf2 -in file.enc  -out file.txt
    220 
    221 # Base64-armored output
    222 openssl enc -aes-256-cbc -a -salt -pbkdf2 -in file.txt -out file.enc
    223 
    224 # Asymmetric (pkeyutl preferred on modern OpenSSL)
    225 openssl pkeyutl -encrypt -pubin -inkey public.key -in plaintext.txt -out encrypted.bin
    226 openssl pkeyutl -decrypt        -inkey private.key -in encrypted.bin -out plaintext.txt
    227 ```
    228 
    229 ---
    230 
    231 ## Hashing
    232 
    233 ```bash
    234 openssl dgst -md5    file.txt
    235 openssl dgst -sha1   file.txt
    236 openssl dgst -sha256 file.txt
    237 openssl dgst -sha512 file.txt
    238 
    239 # Hash a string
    240 echo -n "password" | openssl dgst -sha256
    241 
    242 # HMAC (keyed)
    243 openssl dgst -sha256 -hmac "secret_key" file.txt
    244 echo -n "message" | openssl dgst -sha256 -hmac "key"
    245 ```
    246 
    247 ---
    248 
    249 ## Base64
    250 
    251 ```bash
    252 openssl base64 -in file.bin -out file.b64      # encode
    253 openssl base64 -d -in file.b64 -out file.bin   # decode
    254 echo -n "text" | openssl base64
    255 openssl base64 -A -in file.bin                 # no line breaks
    256 ```
    257 
    258 ---
    259 
    260 ## Passwords & Random
    261 
    262 ```bash
    263 # Unix crypt hashes
    264 openssl passwd -1 "password"    # MD5
    265 openssl passwd -5 "password"    # SHA-256
    266 openssl passwd -6 "password"    # SHA-512
    267 openssl passwd -6 -salt "customsalt" "password"
    268 openssl passwd -apr1 "password" # Apache htpasswd
    269 
    270 # Random data
    271 openssl rand -hex 32
    272 openssl rand -base64 32
    273 openssl rand -out random.bin 256
    274 ```
    275 
    276 > **Tip —** `openssl passwd` output can be injected into `/etc/passwd` or `/etc/shadow` during privilege escalation when you can write those files.
    277 
    278 ---
    279 
    280 ## CSR & Self-Signed Certificates
    281 
    282 ```bash
    283 # CSR with a fresh key
    284 openssl req -new -newkey rsa:2048 -nodes -keyout private.key -out request.csr
    285 
    286 # CSR from an existing key
    287 openssl req -new -key private.key -out request.csr
    288 
    289 # Inspect / verify a CSR
    290 openssl req -in request.csr -text -noout
    291 openssl req -in request.csr -verify
    292 
    293 # Self-signed certificate (1 year)
    294 openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 365 -nodes
    295 
    296 # One-liner with subject
    297 openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes \
    298   -subj "/CN=localhost/O=Test/C=US"
    299 ```
    300 
    301 ---
    302 
    303 ## HTB / Engagement Scenarios
    304 
    305 ```bash
    306 # Windows cert auth via Evil-WinRM
    307 openssl pkcs12 -in user_auth.pfx -nocerts -out user.key -nodes
    308 openssl pkcs12 -in user_auth.pfx -nokeys  -out user.crt
    309 evil-winrm -i target.htb -c user.crt -k user.key -S
    310 
    311 # SSH key from a PFX
    312 openssl pkcs12 -in ssh_cert.pfx -nocerts -out id_rsa -nodes
    313 chmod 600 id_rsa
    314 ssh -i id_rsa user@target
    315 
    316 # ADCS recon from a certificate
    317 openssl x509 -in cert.pem -text -noout | grep -A5  "Issuer"
    318 openssl x509 -in cert.pem -text -noout | grep -A10 "Extensions"
    319 openssl x509 -in cert.pem -text -noout | grep -i   "principal"   # UPN
    320 ```
    321 
    322 ---
    323 
    324 ## Common Options Reference
    325 
    326 | Option | Description |
    327 |---|---|
    328 | `-in <file>` | Input file |
    329 | `-out <file>` | Output file |
    330 | `-text` | Human-readable text output |
    331 | `-noout` | Suppress encoded output |
    332 | `-nodes` | No DES (unencrypted key) |
    333 | `-nocerts` | Don't output certificates |
    334 | `-nokeys` | Don't output private keys |
    335 | `-passin pass:<pwd>` | Input password |
    336 | `-passout pass:<pwd>` | Output password |
    337 | `-inform DER/PEM` | Input format |
    338 | `-outform DER/PEM` | Output format |
    339 | `-CAfile <file>` | CA certificate file |
    340 | `-verify` | Verify signature / certificate |
    341 
    342 ---
    343 
    344 ## Resources
    345 
    346 * Official docs: <https://www.openssl.org/docs/>
    347 * Man pages: `man openssl`, `man openssl-x509`
    348 
    349 > For **authorized security testing only.** Extracting credentials from certificates or testing SSL configurations without permission is illegal.