You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

openssl s_client -showcerts未显示全部证书:负载均衡器新证书验证及到期切换问题

Let me break this down for you step by step, since I’ve dealt with this exact scenario a few times with different load balancer providers:

How to Verify Your New Certificate Was Uploaded Correctly

First, stop relying solely on openssl or browser checks right now—start with your load balancer’s management console, because that’s where the root of the issue likely lies:

  • Check the certificate’s status and binding in the load balancer dashboard
    Log into your load balancer’s admin panel, navigate to the certificate management section, and confirm two things:

    1. Your new certificate shows a status like "Uploaded" or "Active" (no errors like invalid format or missing chain).
    2. Most importantly—the new certificate is actually bound to your 443 HTTPS listener. Uploading a certificate doesn’t automatically assign it to your running services; you have to explicitly update the listener’s certificate configuration to point to the new one.
  • Test with SNI-enabled openssl command
    If your load balancer supports multiple certificates on the same IP (via SNI), your initial command might have pulled the default certificate (the old one) because you didn’t specify the server name. Run this instead:

    openssl s_client -showcerts -connect domainname:443 -servername domainname
    

    This forces the SNI handshake, which should return the certificate tied directly to your domain.

  • Compare certificate fingerprints
    Grab the SHA-256 fingerprint of your new certificate from the load balancer dashboard, then run this command to get the fingerprint of the certificate currently being served:

    openssl s_client -connect domainname:443 < /dev/null | openssl x509 -noout -fingerprint -sha256
    

    If the fingerprints match, the new certificate is live. If not, your listener is still using the old one.

Will the New Certificate Automatically Take Effect When the Old One Expires?

Short answer: No, unless you’ve already configured it to do so. Load balancers don’t magically switch to a new uploaded certificate when the old one expires—here’s what you need to know:

  • If you’ve only uploaded the new certificate but haven’t updated your 443 listener to use it, your service will throw SSL errors once the old certificate expires. There’s no auto-failover to unused uploaded certificates.
  • Some cloud providers offer automatic certificate rotation (if your certificate is issued through their native certificate service). If you have this feature enabled, confirm your new certificate is linked to the rotation policy—otherwise, it won’t auto-switch.
  • The only reliable way to ensure continuity is to:
    1. Update your HTTPS listener to use the new certificate right now.
    2. Wait 5-10 minutes for the load balancer configuration to sync across all nodes.
    3. Re-test with openssl and incognito browser windows (to bypass cache) to confirm the new certificate is being served.

A quick bonus tip: Clear your browser’s SSL cache or use incognito mode when testing—browsers often cache old certificates aggressively, which can give you false results even after the load balancer has updated.

内容的提问来源于stack exchange,提问作者Red Ant

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 15:47:49