Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To check an HTTPS certificate from the command line, connect to the exact host and port, send the hostname with SNI, and require certificate verification. With OpenSSL, run:

openssl s_client -connect example.com:443 -servername example.com -verify_return_error </dev/null

Replace example.com with the hostname you want to test. A successful TLS handshake alone does not prove that the certificate is trusted or matches the hostname; check the verification result and certificate details as well.

What an SSL check tests

“SSL check” is the familiar term, but modern HTTPS uses TLS. A useful check tests the live TLS endpoint—not just a certificate file—and separates several questions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Can the client reach the host and complete a TLS handshake?
  • Does the server present a certificate that is within its validity dates and chains to a trusted root?
  • Does the certificate cover the hostname requested?
  • Which TLS protocol and cipher did the server negotiate?

OpenSSL describes s_client as a generic SSL/TLS client that connects to a remote host. It is a diagnostic tool, so make verification failures explicit when using it to assess whether a normal client should trust the endpoint.

#1 Best Overall
Klein Tools VDV526-200 LAN Scout Jr Cable Tester Ethernet Cable Tester Kit
  • VERSATILE CABLE TESTING: Cable tester for data (RJ45) terminated cables and patch cords, ensuring comprehensive testing capabilities
  • LARGE BACKLIT LCD: Backlit LCD display enables easy reading of pin-to-pin wiremap results, even in low-lit areas
  • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, Split-Pair faults, Cross-over, and Shield, providing thorough fault detection
  • INTUITIVE USER INTERFACE: User-friendly interface with three buttons and simple, easy-to-identify test responses, ensuring a smooth testing experience
  • MULTIPLE TONE GENERATOR STYLES: Tone on a single wire, wire pair, or all 8 conductor wires using the multiple style tone generator (solid/warble); requires probe Cat. No. VDV500-123 (sold separately)

Run a basic HTTPS certificate check with OpenSSL

  1. Open a terminal with OpenSSL installed.

  2. Run the command, replacing the example hostname with the exact DNS name used in the URL:

    openssl s_client -connect example.com:443 -servername example.com -verify_return_error </dev/null
  3. Read the verification result and the handshake output. Check the peer certificate, certificate chain, negotiated protocol, and cipher. With -verify_return_error, verification errors are returned rather than silently allowing the diagnostic session to proceed as if validation succeeded.

    Rank #2
    Klein Tools VDV501-851 Scout Pro 3 Tester Starter Set Cable Tester
    • VERSATILE CABLE TESTING: Cable tester tests voice (RJ11/12), data (RJ45), and video (coax F-connector) terminated cables, providing clear results for comprehensive testing on unenergized Ethernet cables (not designed to test PoE)
    • EXTENDED CABLE LENGTH MEASUREMENT: Measure cable length up to 2000 feet (610 m), allowing for precise cable length determination
    • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, or Split-Pair faults, ensuring thorough fault detection and identification
    • BACKLIT LCD DISPLAY: Backlit LCD screen displays cable length, wiremap, cable ID, and test results, ensuring easy readability in various lighting conditions
    • EFFICIENT CABLE TRACING: Trace cables, wire pairs, and individual conductor wires using the multiple style tone generator (requires analog probe Cat. No. VDV500-123, sold separately), simplifying cable tracing tasks

-connect specifies the destination host and port. -servername sends the DNS hostname using Server Name Indication (SNI). This matters when multiple HTTPS sites share an IP address: without the intended SNI name, the server may present a certificate for a different virtual host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect the certificate fields and names

To print the subject, issuer, validity dates, and Subject Alternative Name (SAN) entries from the server’s presented certificate, use:

Rank #3
NOYAFA NF-8508 Network Cable Tester with Optical Power Meter
  • Multifunctional NOYAFA NF-8508 Network Cable Tester: There are nine features to meet your needs. Continuity Testing, Cable Scan, Port Flash, Length Measurement, POE Power Supply Test, QC testing, Optical Power Meter, VFL and NVC function.It is perfectly suited for various engineering cabling projects, network troubleshooting, network equipment maintenance and testing scenarios. Its precise cable scanning and fault localization capabilities help you effortlessly pinpoint the root cause of issues.
  • 7 WAVELENGTHS OPTICAL POWER METER: NF-8508 network cable tester can measure 7 standard wavelengths, 850/1300/1310/1490/1550/1625/1650, power detecting range(dBm): -70 ~ +10. Its power detection range spans from -70 dBm to +10 dBm, supporting FC/SC/ST connectors. It enables precise fiber optic power measurement, helping users efficiently assess fiber signal strength and ensure healthy fiber link operation. It effortlessly detects attenuation issues within fibers, thereby safeguarding fiber network stability.
  • High Efficiency Visual Fault Locator: Easy identification of fiber breakpoints, poor connections, bending or cracking. Excellent for finding the right fiber to splice or quickly finding a break. Emmiting Energy: standard wavelenth: 650nm. Fast flashing, slow flashing, high precison.The built-in self-calibration ensures stable long-term performance, and Class IIIa laser (output<5mW) ensures safe daily operation.
  • PORT FLASHING:The indicator light on the connection port in the NF-8508 device flashes to help accurately locate the cable. Displays port information, including operating speed, duplex mode, and negotiation settings. Port lights flash on the same screen to show the port's operating speed, making it easy to pinpoint lines and ports.
  • PoE Testing and Cable Length Test: PoE testing can check cable mapping polarity and voltage of PoE network switches, withstand 60VDC. Automatically detects and switches between 10M/100M/1000M modes, Includes cable tracking, short circuit test, interruption of circuit test and etc The RJ45 cable tester can quickly measure the length of the cable with a range of 200m. Not only network cables, but also phone lines and BNC cables.
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates -ext subjectAltName

The SAN list is the key place to check whether the requested DNS name is covered. Certificate verification also checks the chain against the client’s trusted roots and the intended server purpose. OpenSSL’s guidance treats certificate presentation, trusted-chain validation, and hostname matching as distinct checks. Its hostname-verification options describe matching a hostname against a DNS name in SAN or, where applicable, the Common Name.

For an IP-based destination serving a name-based site, connect to the IP but supply the intended DNS name with -servername; the certificate still needs to cover the DNS name the client is meant to use. For protocols such as SMTP or LDAP that begin without TLS, use the appropriate OpenSSL -starttls protocol option rather than treating the service as HTTPS.

Rank #4
Sale
iMBAPrice - RJ45 Network Cable Tester for Lan Phone RJ45/RJ11/RJ12/CAT5/CAT6/CAT7 UTP Wire Test Tool
  • Automatically runs all tests and checks for continuity, open, shorted and crossed wire pairs. Visible LED status display.
  • Cable state testing (2-wire): Line DC detecting, anode and cathode determination,Ringing signal detecting open, short and cross circuit testing
  • Cable Type: RJ11 Telephone cable and RJ45 LAN cable
  • Connectors: Ethernet Cat 5, Ethernet Cat 5e, Ethernet Cat 6, Ethernet Cat 7, RJ11 6P and RJ45 8P
  • Power Source: DC9V Battery Required (not included)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to interpret common SSL check errors

Result or symptom What it usually indicates What to check next
Certificate expired or not yet valid The current time falls outside the certificate’s notBefore and notAfter range. Renew or correct the certificate served by the endpoint, and check the server’s clock.
Unable to get local issuer or incomplete chain The client cannot build a trusted path, often because an intermediate certificate is missing or its trust store lacks the relevant root. Confirm the server sends the required intermediate certificates and that the client uses the expected trust store.
Hostname mismatch The requested name is not covered by the certificate’s SAN (or applicable Common Name). Serve a certificate containing the requested DNS name, or correct the URL or DNS configuration.
Unexpected certificate on a shared IP The server may have selected a different virtual host because the request used the wrong or no SNI name. Repeat the check with the exact intended hostname in -servername and inspect the virtual-host configuration.
Protocol or cipher negotiation failure The client and server may have no mutually supported TLS version or cipher under their current policies. Compare the client’s and server’s TLS settings and supported versions.
Handshake completes but verification fails Negotiation succeeded, but identity or trust validation did not. Treat the check as failed for an ordinary public HTTPS client; a completed handshake is not proof of a valid identity.

OpenSSL notes that versions before 1.1.0 did not perform hostname verification automatically. Legacy scripts should explicitly check the hostname; current automation should also make hostname verification and verification-error handling explicit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Network Ethernet Cable Tester for LAN RJ45 RJ11 CAT5 CAT5E CAT6 CAT6A CAT7, Ethernet Wire Tester Tool UTP/STP Continuity Test for Telephone Line Finder Home Repair (HT812A)
  • Multi-Function Network Cable Tester: Supports RJ45 (CAT5, CAT5e, CAT6, CAT6A, CAT7) and RJ11 telephone cables. Quickly detects continuity, short circuits, open wires, miswiring, and cable shielding status, ensuring your LAN or phone lines are correctly wired and ready to use.
  • Fast/Slow Mode with LED Indicators: Switch between fast and slow scan speeds to identify wiring issues more precisely. LED lights on both master and remote units show wire order, making it easy to spot errors like open pairs or misaligned pins at a glance.
  • Split-Type Design for Long-Distance Testing: Master and remote units can be detached and used separately, allowing you to test both ends of a long cable run, ideal for wall-mounted ports, long runs, or structured cabling. Perfect for home, office, or professional IT setups.
  • Compact, Lightweight & Durable: Ergonomically designed with sturdy ABS housing, this pocket-sized tester is ideal for on-the-go network engineers, DIYers, and electricians. It’s your go-to toolkit for cable maintenance, upgrades, or new installations.
  • Safe & Easy to Use: Simple one-button operation makes testing quick and hassle-free. LED indicators clearly show wiring status, while the G light instantly identifies shielded (FTP/STP) or unshielded (UTP) cables. Supports safe testing of telephone lines with typical voltages under 48-72V, ideal for both home and professional use.

Choose the right kind of check

  • Local command or hosted scanner: a local check is scriptable and keeps the target within your environment; a hosted scanner tests from an external vantage point.
  • Certificate inspection or live handshake: parsing a certificate reveals its fields, while a handshake test also checks reachability, SNI behavior, and negotiated protocol and cipher.
  • One-time diagnosis or monitoring: a one-time command shows the endpoint’s current state. Monitoring is needed to catch later expiry or configuration drift.
  • Public trust or private CA: an internal certificate may be trusted by an organisation’s private CA while failing validation for clients that rely on public trust roots.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.