The -days option specifies the number of days that the certificate will be valid.

rootca/db/serial: A file used to store the serial number of the next certificate to be created for the root CA.


If your server/device requires a different certificate format other than Base64 encoded X. They are Base64 encoded ASCII files.

On a Linux or UNIX system, you can use the openssl command to extract the certificate from a key pair that you downloaded from the OAuth Configuration page.

The text output of the openssl x509 command should include a Subject Public Key section, which will include fields that let you see if it's an RSA or DSA key.

Depending on the certificate, it may contain a URI to get the intermediate from.

On Windows you run Windows certificate manager program using certmgr.
Convert PEM certificate to DER openssl x509 -outform der -in CERTIFICATE.
openssl pkcs7 -print_certs -in certificate.

On Windows systems you can right click the certificate. Export the SSL certificate of a website using Google Chrome: Click the Secure button (a padlock) in an address bar.

Note: OpenSSL is an open source tool. Note: The PEM format is the most common format used for certificates.


We can also get the complete certificate chain. I am using the below openssl command for storing my public key.

