(only the first one if more chained)
$ openssl x509 -in certfile.pem -noout -text
$ openssl x509 -in certfile.pem -noout -pubkey
: do not print the PEM itself (the input)
: print full details
: print PEM public key
$ openssl crl2pkcs7 -nocrl -certfile certchain.pem | openssl pkcs7 -print_certs [-noout]
$ openssl s_client -showcerts -connect <server>:443 </dev/null
$ file privkey.pem
$ openssl pkey -in privkey.pem -noout -check
$ openssl rsa -in privkey.pem -noout -check
$ openssl rsa -in privkey.pem -noout -text
$ openssl rsa -in privkey.pem -pubout
$ openssl rsa -in privkey.pem -pubout | openssl rsa -pubin -noout -text
$ openssl rsa -in pubkey.pem -pubin -noout -text