OPENSSL-VERIFY(1ssl) OpenSSL OPENSSL-VERIFY(1ssl) openssl-verify - openssl verify [-help] [-CRLfile filename|uri] [-crl_download] [-show_chain] [-verbose] [-trusted filename|uri] [-untrusted filename|uri] [-vfyopt nm:v] [-nameopt option] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-engine id] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-provider name] [-provider-path path] [-provparam [name:]key=value] [-propquery propq] [--] [certificate ...] . . -help . -CRLfile filename|uri URI PEM DER. . -crl_download CDP . -show_chain ( ). " " . -verbose . -trusted filename|uri URI ( ). openssl-verification-options(1) . . -untrusted filename|uri URI . . -vfyopt : . . -nameopt . openssl-namedisplay-options(1) . -engine id " " openssl(1). . -engine -trusted -untrusted -CRLfile. -CAfile -no-CAfile -CApath -no-CApath -CAstore _ -no-CAstore "Trusted Certificate Options" openssl-verification-options(1) . -allow_proxy_certs -attime -no_check_time -check_ss_sig -crl_check -crl_check_all -explicit_policy -extended_crl -ignore_critical -inhibit_any -inhibit_map -no_alt_chains -partial_chain -policy -policy_check -policy_print -purpose -suiteB_128 -suiteB_128_only -suiteB_192 -trusted_first -use_deltas -auth_level -verify_depth -verify_email -verify_hostname -verify_ip -verify_name -x509_strict -issuer_checks . " " openssl-verification-options(1) . -provider -provider-path -provparam [:]= -propquery propq " " openssl(1) provider(7) property(7). -- . . -. certificate ... . . - . . . : server.pem: /C=AU/ST=Queensland/O=CryptSoft Pty Ltd/CN=Test CA (1024 bit) error 24 at 1 depth lookup:invalid CA certificate . . ("") 1 CA . . X509_STORE_CTX_get_error(3) . . openssl-verification-options(1), openssl-x509(1), ossl_store-file(7) -show_chain OpenSSL 1.1.0. -engine OpenSSL 3.0. 2000-2026 OpenSSL. . Apache 2.0 ( ""). . LICENSE . 3 . . : . 3.6.2 7 2026 OPENSSL-VERIFY(1ssl)