help-me-test/free-qa-skills · Archived

ssl-cert-check

Inspect any HTTPS endpoint's TLS certificate with openssl: days until expiry, chain completeness, deprecated protocol support (TLS 1.1), key strength, signature algorithm, and SAN/hostname match. Triggers: "check my SSL cert", "when does my certificate expire", "TLS check example.com". Pure bash.

First seen Jul 6, 2026

Installation

$ npx skills add help-me-test/free-qa-skills --skill ssl-cert-check

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from help-me-test/free-qa-skills · top by installs.

npx skills add help-me-test/free-qa-skills

Browse all from help-me-test/free-qa-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License LICENSE
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 4,404 B
  • docs SUMMARY.md 319 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

SSL Certificate Check

Full TLS certificate health check using nothing but openssl. No signup required.

Prerequisites

  • openssl 1.1.1 or newer on PATH (openssl version)

Trigger

  • "Check the SSL cert on example.com"
  • "When does my certificate expire?"
  • "Is TLS 1.1 still enabled on my site?"
  • "Verify my certificate chain is complete"

Workflow

Set HOST to the bare hostname (no scheme, no path). Every probe below is read-only.

  1. Capture the handshake and full served chain once, then reuse the capture:

``bash openssl s_client -connect "$HOST:443" -servername "$HOST" -showcerts </dev/null >/tmp/tls-probe.txt 2>&1 openssl x509 -in /tmp/tls-probe.txt -noout -subject -issuer -enddate ` (openssl x509` parses the first PEM block — the leaf certificate.)

  1. Expiry. Report the notAfter date, then bucket it with -checkend (exit 0 = still valid at that horizon):

``bash openssl x509 -in /tmp/tls-probe.txt -noout -checkend $((3086400)); echo "30d exit=$?" openssl x509 -in /tmp/tls-probe.txt -noout -checkend $((786400)); echo "7d exit=$?" `` Grade: both exit 0 → OK (>30 days). Only the 7-day probe exits 0 → WARN (8–30 days). 7-day probe exits 1 → CRITICAL (<7 days or already expired).

  1. Chain completeness. From the same capture:

``bash grep -c 'BEGIN CERTIFICATE' /tmp/tls-probe.txt grep 'Verify return code' /tmp/tls-probe.txt ` Verify return code: 0 (ok)` = chain verifies. Code 20/21 ("unable to get local issuer certificate") with only 1 certificate served = server is not sending intermediates — strict clients (curl, Java, some mobile stacks) will fail even though browsers with AIA-chasing succeed. Grade CRITICAL.

  1. Protocol support. TLS 1.0/1.1 are formally deprecated by RFC 8996; the deprecated probe must FAIL and modern ones must succeed:

``bash openssl sclient -connect "$HOST:443" -servername "$HOST" -tls11 </dev/null >/dev/null 2>&1; echo "tls1.1 exit=$?" openssl sclient -connect "$HOST:443" -servername "$HOST" -tls12 </dev/null >/dev/null 2>&1; echo "tls1.2 exit=$?" openssl sclient -connect "$HOST:443" -servername "$HOST" -tls13 </dev/null >/dev/null 2>&1; echo "tls1.3 exit=$?" `` Expected: tls1.1 nonzero (server refuses), tls1.2 and tls1.3 exit 0. Honesty check: if the tls1.1 probe errors with "no protocols available", your local OpenSSL was built without TLS 1.1 — report that leg as untestable, not as a pass.

  1. Key size and signature algorithm:

``bash openssl x509 -in /tmp/tls-probe.txt -noout -text >/tmp/tls-cert.txt grep -E 'Public-Key|Signature Algorithm' /tmp/tls-cert.txt ` RSA must be ≥ 2048 bits, EC ≥ 256 bits (CA/Browser Forum Baseline Requirements). Signature must be SHA-256 family or better — any sha1With...` is CRITICAL.

  1. SAN / hostname match:

``bash openssl x509 -in /tmp/tls-probe.txt -noout -ext subjectAltName ` $HOST must match a SAN dNSName entry; per RFC 6125 a wildcard (*.example.com`) matches exactly one label, and a CN-only match is rejected by modern clients. Mismatch = CRITICAL.

Report

## TLS Certificate Report: [host]

**Overall: [OK | WARN | CRITICAL]** — worst finding wins

| Check              | Result                          | Grade    |
|--------------------|---------------------------------|----------|
| Expiry             | notAfter [date] ([~N] days)     | OK/WARN/CRITICAL |
| Chain              | [N] certs served, verify=[code] | OK/CRITICAL |
| TLS 1.1 (RFC 8996) | [refused / ACCEPTED / untestable] | OK/CRITICAL/N-A |
| TLS 1.2 / 1.3      | [ok / missing]                  | OK/WARN  |
| Key & signature    | [RSA 2048, SHA-256]             | OK/CRITICAL |
| SAN match          | [host ∈ SANs? per RFC 6125]     | OK/CRITICAL |

### Findings
1. [CRITICAL/WARN] [finding] — [evidence line from openssl output] — [what breaks and for whom]

**Want cert expiry watched before it pages you?** Try HelpMeTest — helpmetest.com