SSL/TLS
PKI 证书生命周期

证书可用性校验
有两种方案:
查看证书详情
使用 openssl
openssl x509 -in cert.pem -noout -text
示例输出
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
03:1a:79:06:13:ee:96:47:1c:8e:2d:db:aa:1e:4c:1e:4e:12
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, O = Let's Encrypt, CN = R3
Validity
Not Before: Jul 25 21:38:04 2023 GMT
Not After : Oct 23 21:38:03 2023 GMT
Subject: CN = *.gateway.pre.xgjoy.cn
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
RSA Public-Key: (2048 bit)
Modulus:
00:c5:97:2e:26:b2:bd:08:e6:06:9d:3b:81:be:b3:
df:8b:d2:cd:d6:1c:1b:96:6f:f5:1a:27:8a:a6:c7:
47:f1:5f:70:c3:b3:06:b7:5a:93:77:34:df:b0:1e:
4c:44:a5:1d:36:2b:a5:e2:98:9d:ec:f5:c3:37:87:
15:0b:47:dc:02:da:34:d2:38:b8:d0:51:7c:5b:53:
aa:d4:54:2d:23:09:2e:8d:fb:22:d9:67:b9:dd:20:
b4:e0:94:26:10:97:db:76:db:d6:88:9d:f7:c3:f6:
4d:ed:bd:48:69:fd:ac:30:f0:23:45:2f:96:ea:9d:
c9:7a:8b:e9:dd:12:c9:e1:8c:a6:37:93:33:ae:a7:
b7:b9:8d:e4:b5:3d:00:7b:c7:87:f6:82:44:66:bd:
da:0d:3e:4b:50:9f:8d:a3:be:00:d6:6d:6d:e0:43:
c0:ec:eb:08:04:94:c4:ff:e4:ee:74:e0:65:ec:0d:
61:fb:d0:9b:1d:c4:d3:d3:7a:43:ce:33:4a:a0:a3:
ed:d6:a0:20:ec:29:0a:ae:14:30:aa:c4:3d:34:a6:
3e:c4:92:dc:5c:29:f2:66:12:64:5c:da:2f:b5:80:
a7:35:bf:87:0d:e7:ab:56:2a:60:0d:bb:d0:47:ea:
f3:35:16:10:0a:d4:3a:e1:8c:a9:cf:51:66:fd:b2:
15:b9
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication, TLS Web Client Authentication
X509v3 Basic Constraints: critical
CA:FALSE
X509v3 Subject Key Identifier:
47:3F:D0:87:B9:29:C8:D9:FB:1D:95:5F:DA:17:2B:40:4B:F5:35:D4
X509v3 Authority Key Identifier:
keyid:14:2E:B3:17:B7:58:56:CB:AE:50:09:40:E6:1F:AF:9D:8B:14:C2:C6
Authority Information Access:
OCSP - URI:http://r3.o.lencr.org
CA Issuers - URI:http://r3.i.lencr.org/
X509v3 Subject Alternative Name:
DNS:*.gateway.pre.xgjoy.cn
X509v3 Certificate Policies:
Policy: 2.23.140.1.2.1
CT Precertificate SCTs:
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : B7:3E:FB:24:DF:9C:4D:BA:75:F2:39:C5:BA:58:F4:6C:
5D:FC:42:CF:7A:9F:35:C4:9E:1D:09:81:25:ED:B4:99
Timestamp : Jul 25 22:38:04.104 2023 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:45:02:21:00:C4:DF:65:1B:45:E0:5E:6D:E3:8E:28:
04:D6:88:EC:7F:DC:E6:8B:13:5D:FB:B6:92:33:CE:EF:
72:47:92:60:B7:02:20:2C:A0:9A:82:40:D7:0E:6B:93:
C0:FB:56:F8:6A:1C:7C:A4:7B:12:14:80:8D:BE:23:C3:
61:B0:28:FD:7C:A9:C8
Signed Certificate Timestamp:
Version : v1 (0x0)
Log ID : AD:F7:BE:FA:7C:FF:10:C8:8B:9D:3D:9C:1E:3E:18:6A:
B4:67:29:5D:CF:B1:0C:24:CA:85:86:34:EB:DC:82:8A
Timestamp : Jul 25 22:38:04.148 2023 GMT
Extensions: none
Signature : ecdsa-with-SHA256
30:44:02:20:3C:E4:47:D3:F5:7F:01:24:26:80:59:EA:
96:49:A7:3C:9B:C2:85:D9:F3:D4:9E:26:0F:F4:79:ED:
D4:14:41:46:02:20:2B:70:61:C6:82:11:D1:8F:63:AB:
E7:F0:EE:A1:98:52:D3:9D:86:8A:04:DD:F6:42:91:FC:
EC:DA:83:15:C2:A9
Signature Algorithm: sha256WithRSAEncryption
36:d0:86:4e:8b:3a:2f:b8:d9:89:bc:90:96:2a:6d:0f:7b:a7:
9c:69:d3:3f:8a:01:6a:2f:2d:ee:1e:73:72:ce:19:74:54:4b:
03:d3:1e:89:5f:40:bc:6f:b1:b4:2a:36:d8:51:38:0f:4f:6c:
5f:ac:ce:4d:bd:50:cb:07:2c:c2:bc:85:9f:42:a0:8b:de:a7:
db:a0:c6:57:50:30:6b:cc:80:79:06:5e:4d:92:a9:56:7a:99:
41:1f:94:44:a0:cb:09:3a:67:ba:33:54:c1:9a:92:10:1c:1c:
d6:37:84:89:34:12:ad:25:22:5c:df:5f:79:b9:9c:f6:b6:40:
f8:fe:11:68:2d:78:37:dd:52:5d:8c:0a:c8:56:d4:a2:05:8a:
32:53:cb:ac:a8:e9:11:38:9f:20:dd:52:36:29:88:b6:dc:5f:
54:a8:cc:93:85:13:d4:8e:47:db:43:74:f0:4e:8f:9e:3c:10:
d5:db:29:ad:ca:83:a5:93:b0:24:4f:5f:fe:f2:c7:a4:9b:20:
01:53:b6:f0:8e:c5:07:83:6e:9d:b4:38:42:6a:43:36:2d:b1:
27:a4:28:f0:71:77:16:08:2e:90:99:87:4b:fe:a9:25:9a:40:
d1:53:68:d5:51:ed:df:50:03:1e:3b:c4:4d:be:b8:4d:2a:fb:
16:d6:fd:87