tls
Checking a TLS certificate's dates, issuer, and SANs with openssl - 2026-09-05
A handful of openssl x509 flags cover almost everything I need when I just want to inspect a certificate — no need to dump the whole thing with -text unless I'm actually debugging something structural.
Splitting a .pfx into a certificate, key, and CA chain with openssl - 2026-09-05
A .pfx/.p12 file bundles a certificate, its private key, and (usually) the CA chain into one password-protected file — common on Windows and from some CAs. Most Linux tools (nginx, Apache, HAProxy) want those as separate PEM files instead, so it needs splitting apart.
Adding a certificate to a Java keystore/truststore with keytool - 2026-09-05
keytool ships with every OpenJDK install — no separate package needed. It manages both kinds of Java cert stores: a keystore (holds a private key plus its certificate, for a service presenting TLS) and a truststore (just trusted CA certificates, so the JVM knows who to trust…