diff options
author | Daniel Stenberg <daniel@haxx.se> | 2018-08-20 14:05:28 +0200 |
---|---|---|
committer | Daniel Stenberg <daniel@haxx.se> | 2018-08-20 14:05:28 +0200 |
commit | 9dad3bd6652224aa9a1ce1994a082b000243e09c (patch) | |
tree | 1640694d141e48c1360d2b31445527daa319927b | |
parent | a040ff88e4698bdee1eddc0cdb5a7fb65db49201 (diff) | |
download | curl-9dad3bd6652224aa9a1ce1994a082b000243e09c.tar.gz |
SSLCERTS: improve the openssl command line
... for extracting certs from a live HTTPS server to make a cacerts.pem
from them.
-rw-r--r-- | docs/SSLCERTS.md | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/docs/SSLCERTS.md b/docs/SSLCERTS.md index 3fcd345b0..2c5be68e6 100644 --- a/docs/SSLCERTS.md +++ b/docs/SSLCERTS.md @@ -92,8 +92,8 @@ server, do one of the following: If you use the 'openssl' tool, this is one way to get extract the CA cert for a particular server: - - `openssl s_client -connect xxxxx.com:443 |tee logfile` - - type "QUIT", followed by the "ENTER" key + - `openssl s_client -showcerts -servername server -connect server:443 > cacert.pem` + - type "quit", followed by the "ENTER" key - The certificate will have "BEGIN CERTIFICATE" and "END CERTIFICATE" markers. - If you want to see the data in the certificate, you can do: "openssl |