tannylab / tls

When does this certificate run out?

Reads the certificate a server is actually presenting, checks the chain and hostname, and lays out what you need to renew it: who issued it, whether CAA allows the reissue, and the commands to get there.

What we found

    Renewing it

    Based on the issuer, DNS and CAA policy

    Certificate

    Chain as served

    Leaf first, in the order the server sent it

      Issued certificates

      Unexpired certs for this name in public Certificate Transparency logs

      Waiting on crt.sh…

      Take it with you