some openssl test commands

convert a pkcs7 (.p7b) file to an x509 (.pem/.crt) file

★ openssl pkcs7 -print_certs -in my_groovy.p7b -out my_groovy.pem

check if an x509 .crt and .key belong together

★ openssl x509 -noout -modulus -in my_groovy.crt | openssl md5

★ openssl rsa -noout -modulus -in my_groovy.key | openssl md5

check a url's certificate expiry

★ echo | openssl s_client -connect | openssl x509 -noout -dates
depth=1 /C=US/O=DigiCert Inc/CN=DigiCert SHA2 Secure Server CA
verify error:num=20:unable to get local issuer certificate
verify return:0
notBefore=Feb 20 00:00:00 2019 GMT
notAfter=Feb 23 12:00:00 2020 GMT