How To Quickly Verify Certificate Chain Files Using OpenSSL

As a final note, with "-partial_chain" any certificate always verifies against itself regardless of purpose or basic constraints. Thus, for example: $ openssl verify -partial_chain -purpose crlsign foo.pem foo.pem will always succeed, provided foo.pem contains a certificate that does not fail to parse. Verifying that a Private Key Matches a Certificate Oct 04, 2005 OpenSSL - OpenSSL "s_client -connect" - Show Server