Verificar de uma maneira simples o certificado, a chave e o csr:
# Private Key
openssl ec -in domain.key -pubout | openssl md5
# CSR
openssl req -in domain.csr -noout -pubkey | openssl md5
# Certificate from CA (Certificate Chain or Leaf Certificate, both will give same result)
openssl x509 -in domain.crt -pubkey -noout | openssl md5
O resultado da hash md5 devem ser os mesmos.