openssl s_client -connect <host>:443
Inspect a live TLS certificate chain
Enter a hostname to fetch its live TLS certificate. Shows the server-presented chain, completes it toward a trust anchor where safely possible, and reports hostname and trust validation separately from inspection — a broken certificate can still be inspected.
Examples: github.com cloudflare.com expired.badssl.com
PAN-OS EDL Certificate Profile workflow
// which certificates a Palo Alto Certificate Profile needs for this HTTPS EDL, and why · The URL is sent by POST and is not stored by Pixtria. Query parameter values are redacted in the displayed results. URL path segments may be shown, so do not place secrets in the URL path.
Enter an HTTPS EDL source URL to determine which CA certificates a PAN-OS Certificate Profile needs, trace the retrieval path across redirects, and run a safe basic transport preflight. Pixtria does not accept EDL credentials and never stores or logs the URL.