Skip to main content

Servier Inspired PyPI package FreeBSD port

Installation

Once you have installed Python and its packages manager pip, use one of the following commands, depending on if you want only this tool, the full set of PNU tools, or PNU plus a selection of additional third-parties tools:

pip install pnu-certwatch
pip install PNU
pip install pytnix

CERTWATCH(1)

NAME

certwatch - Watch X509 certificates expiration dates

SYNOPSIS

certwatch [--delay|-d SEC] [--excel|-e FILE] [--filter|-f DAYS] [--ip|-i] [--new|-n] [--noaltnames|-a] [--noprogress|-b] [--savedir|-s DIR] [--timeout|-t SEC] [--debug] [--help|-?] [--version] [--] file [...]

DESCRIPTION

The certwatch utility monitors X509 certificates expiration dates by processing one or more data files containing lists of hostnames with optional port numbers.

It's mainly used to check the expiration date of HTTPS certificates (which is the default target when the port number is not indicated), but the tool is protocol-agnostic and can "talk" to any SNI-aware (Server Name Information) SSL/TLS server (smtps, imaps, ldaps, etc.) without making too much assumptions on the correctness of servers certificates.

The certificates can be saved to a specified directory with the --savedir|-s option for further analysis with other tools (such as OpenSSL).

As it's intended to bulk process a lot of certificates, a progress bar is displayed (can be removed with the --noprogress|-b option) and the time allowed to get a certificate is limited to a 10 seconds timeout (can be specified otherwise with the --timeout|-t option, but is not supported on Windows systems).

In order to avoid doing a Denial of Service attack on servers hosting many certificates, a 1 second delay is waited between each certificate request (can be specified otherwise with the --delay|-d option).

The tool results are presented as text tables.

The main one is the list of certificates successfully fetched, ordered by expiration date. This list can be filtered with the --filter|-f option to only show certificates expired or expiring within the specified number of days. You can use the --noaltnames|-a option in order to stop displaying alternate names contained in certificates, or the --ip|-i option to include the IP addresses of servers.

The second table is the sorted list of hostnames / hostports where certificates couldn't be fetched, with our best attempts to identify the reason why.

Two additional tables can be generated with the --new|-n option, in order to print the common names and alternate names unmentioned in your input data files.

Finally, for user convenience, all these reports can be generated in a single multi-tabs Excel workbook specified with the --excel|-e option.

OPTIONS

Options Use
--delay|-d SEC Wait SEC (0-N) seconds between requests
--excel|-e FILE Output results in Excel FILE
--filter|-f DAYS Show results expiring in less than DAYS
--ip|-i Show IP address of hostnames
--new|-n Show unmentioned CN/alt names in input files
--noaltnames|-a Don't show alt names in results
--noprogress|-b Don't use a progress bar
--savedir|-s DIR Save certificates in DIR directory
--timeout|-t SEC Wait SEC (1-N) seconds before aborting a request
--debug Enable debug mode
--help|-? Print usage and a short help message and exit
--version Print version and exit
-- Options processing terminator

ENVIRONMENT

The CERTWATCH_DEBUG environment variable can be set to any value to enable debug mode.

FILES

/usr/local/share/certwatch/tests.txt - config file example using the badssl.com Web site for testing live bogus X509 certificates, with text and Excel output.

The structure of configuration files is as follows:

  • Everything after a '#' character is a comment
  • Blank lines are allowed
  • data lines are either:
    • "hostname hostport"
    • "hostname"
  • When hostport is not provided, port 443 (HTTPS) is assumed

EXIT STATUS

The certwatch utility exits 0 on success, and >0 if an error occurs.

EXAMPLES

The following command will make certwatch process your certificates list in mycertslist.txt, save all certificates in PEM format to mycertsdir, print all possible reports and details to screen and to an Excel workbook named certwatch.out.xlsx, and select or highlight certificates expired or set to expire in the coming 30 days:

# certwatch -in -e certwatch.out.xlsx -s mycertsdir -f 30 mycertslist.txt | tee certwatch.out.txt

Saved certificates can then be viewed with the openssl command like this for a mycert.pem file:

# openssl x509 -inform PEM -in mycert.pem -noout -text | more

SEE ALSO

openssl(1)

STANDARDS

The certwatch utility is not a standard UNIX command.

It tries to follow the PEP 8 style guide for Python code.

PORTABILITY

Tested OK under Windows.

Packaged for FreeBSD as pyXX-pnu-certwatch.

HISTORY

This implementation was made for the PNU project.

Both for my own needs and those of my company, I wanted an easy way to monitor thousands of certificates expiration dates.

The initial idea was to use the tool to send an email report of the certificates about to expire, but an Excel report in order to perform all kind of sorts and filtering was quickly necessary...

LICENSE

It is available under the 3-clause BSD license.

AUTHORS

Hubert Tournier

CAVEATS

Using this command through outgoing proxies is untested and we provide no option to set the proxy address. However it should work through reverse proxies on the server side.

SECURITY CONSIDERATIONS

When certificate retrieval is unsuccessful, certwatch will try to diagnose the issue in different ways, one of which involving running the system ping command. This can be an issue if someone happens to place a command with the same name higher in your PATH. But working at the IP layer level, which is needed in order to implement the ICMP protocol, requires root privileges which I see as a bigger risk...

Release files for pnu-certwatch 1.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pnu-certwatch 1.0.3
File Size Uploaded
pnu-certwatch-1.0.3.tar.gz 22.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pnu-certwatch 1.0.3
File Interpreter ABI Platform
pnu_certwatch-1.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 40.8 kB

Release files / pnu-certwatch-1.0.3.tar.gz

Download URL pnu-certwatch-1.0.3.tar.gz
Size 22.1 kB
Tags Source
SHA-256 checksum
How to use checksums
e736811765f567cb427035eb8449196638c1ea8ef7cb68755a58b2668b400f44
BLAKE2b-256 checksum
How to use checksums
a69c83f14693d0c168377f76f247a9dffa228b1f26c8586a504900166860cff7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.9.18

Release files / pnu_certwatch-1.0.3-py3-none-any.whl

Download URL pnu_certwatch-1.0.3-py3-none-any.whl
Size 18.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b0ed6bcf5ff23fd3c82f4a9bdec2545b4ace4aeefa91c12b87bc174ec2d9bfc7
BLAKE2b-256 checksum
How to use checksums
d2c7392efc9cde32d462f8c225f9544b6fb2783298159e2eb5fb642710bbf38a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.0.0 CPython/3.9.18

Release history Release notifications | RSS feed

This release

1.0.3 This release

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page