bg-tutorials

如何使用 OpenSSL 检查 SSL 证书的到期日期

SSL 证书的有效期是有限的,必须定期续期才能持续获得浏览器的信任。2026 年 3 月 15 日之后颁发的公共证书有效期最长为 200 天,最长有效期将在 2027 年 3 月 15 日降至 100 天,在 2029 年 3 月 15 日降至 47 天。准确了解证书何时到期,有助于你按时续期并避免服务中断。

本指南将向你展示如何使用 OpenSSL 检查证书过期时间:包括在线服务器和本地文件两种情况,以及如何检查证书是否即将到期。

快速答案:

对于在线网站,运行:

echo | openssl s_client -connect yourdomain.com:443 -servername yourdomain.com 2>/dev/null | openssl x509 -noout -enddate. 

对于证书文件,运行:

openssl x509 -in your_certificate.pem -noout -enddate. 

notAfter 值即为过期日期。

方法一:检查在线服务器上的证书

此方法通过连接到正在运行的网站并读取其提供的证书来实现,你不需要证书文件。它适用于任何可访问的主机(远程域名,或使用正确端口的 localhost 本地服务器)。

在 Linux 和 macOS 上

echo | openssl s_client -servername yourdomain.com -connect yourdomain.com:443 2>/dev/null | openssl x509 -noout -enddate

将 yourdomain.com 替换为你的实际域名。由于 macOS 是类 Unix 系统(其内置的 openssl 实为 LibreSSL,支持这些选项),因此该命令在 macOS 上也是相同的。

在 Windows 上

  • 打开命令提示符或 PowerShell(按 Win + R,输入 cmd 或 powershell,然后按 Enter)。
  • 运行:
echo | openssl s_client -servername yourdomain.com -connect yourdomain.com:443 2>nul | openssl x509 -noout -enddate

在 Windows 上,使用 2>nul 代替 2>/dev/null 来丢弃错误信息。

方法二:从 PEM 文件检查证书

PEM 文件是一种以 base64 编码的证书,以 —–BEGIN CERTIFICATE—– 开头,以 —–END CERTIFICATE—– 结尾。当你的磁盘上存有证书文件时,可使用此方法。

在 Linux 和 macOS 上

切换到存放证书的文件夹,然后读取其到期日期(将 your_certificate.pem 替换为你的文件名):

cd /path/to/your/certificate/directory
openssl x509 -in your_certificate.pem -noout -enddate

在 Windows 上

cd C:pathtoyourcertificatedirectory
openssl x509 -in your_certificate.pem -noout -enddate

请确保已安装 OpenSSL 并将其添加到系统 PATH 中;否则,请指定 openssl.exe 可执行文件的完整路径。

查看两个日期,或检查证书是否即将到期

要同时查看颁发日期(notBefore)和到期日期(notAfter),请使用 -dates 而不是 -enddate:

openssl x509 -in your_certificate.pem -noout -dates

要检查证书是否会在给定的时间窗口内到期,请使用 -checkend 并指定秒数(此处 2592000 秒 = 30 天):

openssl x509 -in your_certificate.pem -noout -checkend 2592000

它会打印出 Certificate will not expire(并以状态码 0 退出)或 Certificate will expire(状态码 1)——这使其非常适合用于监控脚本和 cron 定时任务。

理解命令和输出结果

以在线服务器命令及其输出为例:

echo | openssl s_client -servername example.com -connect example.com:443 2>/dev/null | openssl x509 -noout -enddate

输出:

notAfter=Sep 15 23:59:59 2026 GMT

以下是各部分的作用:

  • echo | —— 发送空输入,使命令无需等待交互即可完成。
  • openssl s_client —— 打开与服务器的 SSL/TLS 连接。
  • -servername example.com —— 设置服务器名称指示(SNI),当服务器为不同域名托管多个证书时,此项为必需。
  • -connect example.com:443 —— 要连接的主机和端口(443 端口是标准的 HTTPS 端口)。
  • 2>/dev/null(Linux/macOS)或 2>nul(Windows)—— 丢弃错误信息,只显示相关输出。
  • | openssl x509 -noout -enddate —— 将证书传递给 x509 工具;-noout 抑制 PEM 数据的输出,-enddate 仅打印到期日期。
  • notAfter=… —— 证书失效的日期和时间。

自动化处理:不再手动追踪日期

与手动检查到期日期相比——尤其是随着有效期逐渐缩短至 47 天——你可以使用作为证书即服务(CaaS)的 ACME。它可以处理域名验证、安装证书,并在证书到期前自动续期,从而让你的网站始终保持受信任状态,无需人工干预。

立即订购 SSL 证书, 可节省 10% 的费用!

快速发行, 强大加密, 99.99% 的浏览器信任度, 专业支持和 25 天退款保证. 优惠券代码 SAVE10

龙飞行的详细图像
撰写人

经验丰富的内容撰稿人, 擅长 SSL 证书. 将复杂的网络安全主题转化为清晰, 引人入胜的内容. 通过有影响力的叙述, 为提高数字安全作出贡献.

Avatar of Sergiu Rosca
Technical Review by Sergiu Rosca

Sergiu Rosca is the core web developer behind SSL Dragon. He manages the technical infrastructure, platform performance, and backend integrations that keep the site running smoothly and securely. At SSL Dragon, Sergiu shares practical insights on web development, site optimization, and technical troubleshooting.

All SSL Dragon installation guides are tested on live server environments and undergo a strict peer-review process to ensure your infrastructure remains secure. Read our full Editorial Policy.