Complete OpenSSL keyboard shortcuts and commands reference — 14 shortcuts across 1 category. Quick reference cheat sheet for Windows & Mac.
OpenSSL's command line is where certificates are made, inspected and debugged, and the fourteen commands here cover the certificate lifecycle plus the hashing and encryption one-liners people reach for. The notes follow the order of getting a certificate — key, request, signature — and the two commands that answer "why is TLS failing".
| Shortcut | Action | Description |
|---|---|---|
| openssl req -new -x509 -newkey rsa:2048 | Self-signed cert | Generate self-signed SSL certificate. |
| openssl x509 -in cert.pem -text | View cert | View certificate contents. |
| openssl s_client -connect host:443 | Test SSL | Test SSL connection. |
| openssl rsa -in key.pem -check | Verify key | Verify RSA key. |
| openssl rand -base64 32 | Generate random | Generate 32-byte random string. |
| openssl genrsa -out key.pem 2048 | Generate RSA key | Create a new 2048-bit RSA private key. |
| openssl req -new -key key.pem -out csr.pem | Create CSR | Generate a certificate signing request from a key. |
| openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem | Sign CSR | Self-sign a CSR to produce a certificate. |
| openssl x509 -enddate -noout -in cert.pem | Check expiry | Print the certificate expiration date. |
| openssl verify cert.pem | Verify cert | Verify a certificate against the trust store. |
| openssl dgst -sha256 [file] | SHA-256 checksum | Compute the SHA-256 digest of a file. |
| openssl enc -aes-256-cbc -in f -out f.enc | Encrypt file | Encrypt a file with AES-256-CBC. |
| openssl enc -d -aes-256-cbc -in f.enc -out f | Decrypt file | Decrypt an AES-256-CBC encrypted file. |
| openssl pkcs12 -export -out bundle.p12 -inkey key.pem -in cert.pem | PKCS#12 bundle | Bundle a key and certificate into a .p12 file. |
The most essential OpenSSL shortcuts are: openssl req -new -x509 -newkey rsa:2048 (Self-signed cert), openssl x509 -in cert.pem -text (View cert), openssl s_client -connect host:443 (Test SSL).
These are command-line commands — type them in your terminal or console. Combine them with shell history search (Ctrl + R) and aliases to work even faster.
The OpenSSL shortcut for self-signed cert is openssl req -new -x509 -newkey rsa:2048. Generate self-signed SSL certificate.
Print the OpenSSL cheat sheet and keep it next to your keyboard for the first week, then switch to active recall: open Shortcut Speedrun and practice OpenSSL shortcuts against the clock until they're automatic.
Yes — use My Stack to combine OpenSSL shortcuts with any other platform on this site into one printable reference, which is useful if your daily workflow spans several tools.
openssl genrsa -out key.pem 2048 generates a private key (use 3072 or an EC key for new deployments), and openssl rsa -in key.pem -check verifies it is intact. openssl req -new -key key.pem -out csr.pem creates a certificate signing request for a CA, and openssl x509 -req -in csr.pem -signkey key.pem -out cert.pem self-signs that request when no CA is involved. openssl req -new -x509 -newkey rsa:2048 does key and self-signed certificate in one step for a test server. openssl pkcs12 -export -out bundle.p12 -inkey key.pem -in cert.pem bundles key and certificate for Windows, Java keystores and browsers.
openssl x509 -in cert.pem -text prints everything in a certificate — subject, SANs, issuer, validity, extensions — and openssl x509 -enddate -noout -in cert.pem just the expiry, which monitoring scripts poll. openssl verify cert.pem checks the chain against the system CA store (add -CAfile for a private CA). openssl s_client -connect host:443 performs a TLS handshake and prints the certificate chain the server actually sends, which is how "works locally, fails in production" gets diagnosed; add -servername host for SNI and -showcerts for the full chain.
openssl dgst -sha256 [file] prints a checksum for verifying downloads, and openssl rand -base64 32 generates a random secret for a config file. openssl enc -aes-256-cbc -in f -out f.enc encrypts a file with a passphrase and openssl enc -d -aes-256-cbc -in f.enc -out f decrypts it; add -pbkdf2 to both, as current OpenSSL warns, and prefer age or gpg for anything long-lived.
Open your assistant with this page preloaded as the source — great for follow-up questions like "which of these work in other apps?"