Web Server Rescue
Read-only, sensitive outputShow TLS Certificate Names
The certificate is unexpired but users still see a hostname warning, so you need to inspect the served subject and SAN names.
Command
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName
Before you run this
System impact: Read-only. Output may expose users, paths, tokens, keys, IPs, process arguments, or log details.
When not to use it: Do not rely on the common name alone. Modern clients validate SAN names, and SNI can change which certificate is served.
Expected output
Certificate subject plus `subjectAltName` entries, where the hostname users type should appear.
System impact
Read-only, sensitive output. Nothing changes. The command performs a read-only TLS handshake and prints certificate identity fields.
Recovery / rollback: no state is changed.
When to use it
Use when browsers report a hostname mismatch, a CDN serves the wrong certificate, or apex and `www` behave differently.
When not to use it
Do not rely on the common name alone. Modern clients validate SAN names, and SNI can change which certificate is served.
next steps
Related commands
Check the Certificate Served for SNI
The IP was right. The SNI name selected the wrong certificate.
openssl s_client -connect example.com:443 -servername www.example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -ext subjectAltName
Show TLS Certificate Dates
The outage was not the web server. The edge certificate had expired.
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -dates
Show Served Certificate SANs
SANs decide which hostnames the certificate covers.
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -ext subjectAltName
Show TLS Protocol and Cipher
The certificate was fine. The TLS negotiation told the rest of the story.
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | awk '/Protocol|Cipher|Verify return code/ {print}'
Read TLS Certificate Subject and Issuer
The certificate can be valid but issued for the wrong name.
openssl s_client -connect example.com:443 -servername example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates
Study mapping
Use this as independent command practice: read the notes, predict the output, then compare it with the example before using a real shell.
Independent study support only. No affiliation, endorsement, exam dumps, or real exam questions.