4 ms·
Apart from genrsa, what exactly have you used the openssl cli for in the past? My answer would be the exact same as you quoted, the openssl cli tools are quite
by dekz 13y ago
Apart from genrsa, what exactly have you used the openssl cli for in the past?
My answer would be the exact same as you quoted, the openssl cli tools are quite horrendous to use and you certainly wouldn't use them if you were a CA. If you are a CA or deal with certificates, openssl does provide sweet inspection dumping tools for asn1 and certs.
If you have an application which generates keys or certificates, why would you system exec openssl cli when your language of choice has a Crypto implementation, or glue to OpenSSL.
So I ask openly, run `history | grep openssl` and see. Even running `openssl help` is daunting unless you're familiar with most symmetric block modes.
- ryan-c 13y agoThere are a number of tools for running a small CA that wrap the OpenSSL command line tools.
- pjungwir 13y agoI use the openssl cli every time I generate a CSR or a self-signed certificate. If you Google "generate csr" you'll find lots of sites, including companies that issue SSL certificates, instructing you to use the openssl cli.
- chrisbolt 13y agoopenssl s_client -connect <hostname>:<port> Also for conversion of certificates to different formats and removing passphrases from existing certificates.
- mmastrac 13y agoI've used them a ton for ASN.1 parsing, base64 encoding/decoding, hashing, certificate dumping and the occasional RSA decryption or signature check. The command-line interface is horrendous, but man is that a useful crypto toolbox.
- FiloSottile 13y agoAll the responses in this thread, plus one-off symmetrically encrypting files.