#!/bin/sh openssl x509 -purpose -in clientcert.pem -inform PEM -noout