OpenSSL for Reconnaissance

OpenSSL is a powerful, open-source command-line tool that can be used for various cryptographic tasks, including SSL/TLS testing and reconnaissance.

Checking SSL/TLS Certificates with s_client

The s_client command can be used to establish an SSL/TLS connection to a remote host and retrieve its certificate information. This is useful for verifying the certificate chain, expiration dates, and other details during reconnaissance.

Command

To connect to a host and display its SSL/TLS certificate chain:

openssl s_client -connect <FQDN>:443 -servername <FQDN> -showcerts
  • <FQDN>: Replace with the Fully Qualified Domain Name of the target server.
  • 443: The standard port for HTTPS. Change if the service runs on a different port.
  • -servername <FQDN>: Specifies the server name indication (SNI), which is important for servers hosting multiple TLS certificates.
  • -showcerts: Displays the entire certificate chain sent by the server.

Example

openssl s_client -connect example.com:443 -servername example.com -showcerts

This command will output a lot of information, including the server’s certificate, intermediate certificates, and root certificate, along with connection details. You can further process this output using grep or other tools to extract specific information.