How to Inspect a Certificate
This guide shows you how to read the details of a certificate held in a file, served by a live endpoint, or tracked as a cert-manager Certificate, and how to list expiry dates across a cluster.
Type |
How-to guide |
Goal |
Read a certificate’s subject, issuer and validity window, wherever that certificate currently lives. |
Audience |
Platform Operator who can read Secrets and Certificates in the target namespace, or anyone holding the certificate file. |
When to use |
Use this guide when confirming which certificate a component presents, or when checking what is close to expiring. |
Prerequisites
Confirm the following before you begin.
Access and permissions required
You need the following access and permissions:
-
Read access to the certificate file, or to the Secret that holds it.
-
Permission to list
Certificateresources in the namespace, for the cluster-wide expiry check.
Tools and versions required
You need the following tools:
-
openssl, either installed locally or run from a pod. The Apache Kafka broker pods already have it. -
kubectl>= 1.28, for the cluster-wide expiry check only. -
KeyStore Explorer, for inspecting or editing a keystore or truststore file.
Resources that must exist before starting
The following must already exist:
-
cert-manager, for the cluster-wide expiry check. Without it there are no
Certificateresources to list.
The certificate below is a public root CA in PEM format, usable as sample input for the commands in this guide.
Example root CA certificate in PEM format
-----BEGIN CERTIFICATE-----
MIIDrzCCApegAwIBAgIQCDvgVpBCRrGhdWrJWZHHSjANBgkqhkiG9w0BAQUFADBh
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBD
QTAeFw0wNjExMTAwMDAwMDBaFw0zMTExMTAwMDAwMDBaMGExCzAJBgNVBAYTAlVT
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
b20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IENBMIIBIjANBgkqhkiG
9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4jvhEXLeqKTTo1eqUKKPC3eQyaKl7hLOllsB
CSDMAZOnTjC3U/dDxGkAV53ijSLdhwZAAIEJzs4bg7/fzTtxRuLWZscFs3YnFo97
nh6Vfe63SKMI2tavegw5BmV/Sl0fvBf4q77uKNd0f3p4mVmFaG5cIzJLv07A6Fpt
43C/dxC//AH2hdmoRBBYMql1GNXRor5H4idq9Joz+EkIYIvUX7Q6hL+hqkpMfT7P
T19sdl6gSzeRntwi5m3OFBqOasv+zbMUZBfHWymeMr/y7vrTC0LUq7dBMtoM1O/4
gdW7jVg/tRvoSSiicNoxBN33shbyTApOB6jtSj1etX+jkMOvJwIDAQABo2MwYTAO
BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUA95QNVbR
TLtm8KPiGxvDl7I90VUwHwYDVR0jBBgwFoAUA95QNVbRTLtm8KPiGxvDl7I90VUw
DQYJKoZIhvcNAQEFBQADggEBAMucN6pIExIK+t1EnE9SsPTfrgT1eXkIoyQY/Esr
hMAtudXH/vTBH1jLuG2cenTnmCmrEbXjcKChzUyImZOMkXDiqw8cvpOp/2PV5Adg
06O/nVsJ8dWO41P0jmP6P6fbtGbfYmbW0W5BjfIttep3Sp+dWOIrWcBAI+0tKIJF
PnlUkiaY4IBIqDfv8NZ5YBberOgOzW6sRBc4L0na4UU+Krk2U886UAb3LujEV0ls
YSEY1QSteDwsOoBrp+uvFRTp2InBuThs4pFsiv9kuXclVzDAGySj4dzp30d8tbQk
CAUw7C29C79Fv1C5qfPrmAESrciIxpg0X40KPMbp1ZWVbd4=
-----END CERTIFICATE-----
Inspect a certificate file
Run openssl x509 against a PEM file to read its subject, issuer, validity window and friendly name.
Replace every <VALUE> placeholder with your own value before running a command.
|
openssl x509 -in <CERTIFICATE_FILE>.pem -subject -issuer -dates -alias
To read a certificate out of a Kubernetes Secret rather than a file, decode the Secret entry first. Verify the certificate a Secret carries gives that command.
Inspect the certificate an endpoint serves
Run openssl s_client against a live endpoint to see what it presents, rather than what its configuration says it should.
openssl s_client -connect <HOST>:<PORT> -showcerts
The output holds the full certificate chain, with the common name (CN) and expiry date of each certificate in it. The Acceptable client certificate CA names section lists the root certificate authorities the endpoint trusts, which is what to check when a client certificate is being rejected.
List certificate expiry across the cluster
Ask for every cert-manager Certificate in the namespace and filter the output down to the name, expiry and renewal time of each.
kubectl get certificates -o json | grep '"name"\|notAfter\|renewalTime'
Expected output pairs each certificate with the issuer that signed it and its two dates:
"name": "app-one",
"name": "axual-dummy-cluster-issuer"
"notAfter": "2025-04-04T20:22:16Z",
"renewalTime": "2025-03-20T20:22:16Z"
"name": "axual-rest-proxy",
"name": "axual-dummy-cluster-issuer"
"notAfter": "2025-03-05T16:23:13Z",
"renewalTime": "2025-02-18T16:23:13Z",
| For an ongoing view rather than a one-off check, import the cert-manager Grafana dashboard, which reports the same status graphically. |
Inspect a keystore or truststore
Open the file in KeyStore Explorer when the certificate sits inside a keystore or truststore rather than in a PEM file. It shows the full detail of each entry, and it can create and edit keystores and truststores, including extracting a certificate and private key from a JKS file.
Decode a certificate without a local tool
Paste the certificate into an online decoder such as sslchecker.com/certdecoder when no local tooling is available.
| Never paste a private key into an online tool. Certificates are public; private keys are not, and pasting one compromises it permanently. |