A robust, user-friendly Python CLI tool for inspecting SSL/TLS certificates of remote servers.
Project description
ssl-checkup
A robust, modular Python CLI tool for inspecting SSL/TLS certificates of remote servers. Features comprehensive testing, clean architecture, colorized output, and detailed debugging capabilities.
Features
- Certificate Analysis: Check SSL certificate validity, issuer, subject, and SANs for any host
- Colorized Output: Beautiful, readable output with
--no-coloroption for plain text - Debug Mode: Comprehensive troubleshooting with
--debugflag - Flexible Output: Print PEM certificate, issuer, subject, or SANs only as needed
- Error Handling: Graceful handling of DNS/socket errors with helpful messages
- Modular Architecture: Clean, testable code structure with 95% test coverage
- Easy Installation: Available on PyPI - install with
pipx install ssl-checkup
Installation
For Users (Recommended)
Install with pipx for best isolation and to avoid dependency conflicts:
pipx install ssl-checkup
If you don't have pipx, install it first:
# On macOS with Homebrew
brew install pipx
# On Ubuntu/Debian
sudo apt install pipx
# Or with pip
pip install --user pipx
pipx ensurepath
Alternative: Install with pip (may cause dependency conflicts):
pip install ssl-checkup
After installation, run from anywhere:
ssl-checkup example.com
For Development
Clone and set up development environment:
git clone https://github.com/BaDxKaRMa/ssl-checkup.git
cd ssl-checkup
# Using uv (recommended)
uv sync
uv run ssl-checkup example.com
# Or using pip
pip install -e ".[dev,test]"
python -m ssl_checkup.main example.com
Usage
ssl-checkup [OPTIONS] WEBSITE[:PORT]
Arguments:
WEBSITE- Domain or IP address to check (default port: 443)PORT- Optional custom port (e.g.,example.com:8443)
Options
| Option | Description |
|---|---|
--no-color |
Disable color output for plain text |
-p, --print-cert |
Print the PEM certificate to stdout |
--debug |
Enable debug output for troubleshooting |
-i, --issuer |
Print only the certificate issuer |
-s, --subject |
Print only the certificate subject |
-a, --san |
Print only the Subject Alternative Names (SANs) |
--insecure, -k |
Allow insecure connections (bypass certificate validation) |
--version |
Show version and exit |
-h, --help |
Show help message |
Examples
Basic certificate check:
ssl-checkup example.com
Check custom port:
ssl-checkup example.com:8443
Print specific certificate fields:
ssl-checkup -i example.com # Issuer only
ssl-checkup -s example.com # Subject only
ssl-checkup -a example.com # SANs only
Debug and troubleshooting:
ssl-checkup --debug example.com # Detailed debug output
ssl-checkup --insecure expired.badssl.com # Skip validation
Export certificate:
ssl-checkup -p example.com > cert.pem # Save PEM certificate
ssl-checkup --no-color example.com > info.txt # Plain text output
Requirements
- Python: 3.11 or higher
- Optional Dependencies:
termcolor>=3.1.0(enhanced colorized output)cryptography>=45.0.5(advanced certificate parsing)
Note: The tool works without optional dependencies, with graceful fallbacks for missing features.
Development
Quick Start
# Clone and set up development environment
git clone https://github.com/BaDxKaRMa/ssl-checkup.git
cd ssl-checkup
uv sync
# Run tests
make test
# Run with coverage
make test-coverage
# Run all quality checks
make check-all
Contributing
- Fork and clone the repository
- Set up development environment:
uv sync - Run tests to ensure everything works:
make test - Make your changes with appropriate tests
- Run quality checks:
make check-all - **Submit a pull request`
Releasing (Maintainers)
This project uses automated PyPI publishing via GitHub Actions. To release a new version:
Option 1: Using Makefile (Recommended)
# Create and push a new release in one command
make release-push VERSION=1.1.0
Option 2: Manual Process
# 1. Update version in pyproject.toml
version = "1.1.0"
# 2. Commit and tag the release
git add pyproject.toml
git commit -m "Release v1.1.0"
git tag v1.1.0
# 3. Push to trigger automated PyPI upload
git push && git push --tags
What happens automatically:
- GitHub Actions builds the package with
uv - Runs quality checks with
twine check - Uploads to PyPI using stored API token
- New version is available within minutes
Requirements for automated releases:
- PyPI API token stored in GitHub Secrets as
PYPI_API_TOKEN - Version must follow semantic versioning (e.g., 1.0.0, 1.1.0, 2.0.0)
Troubleshooting
Common Issues
Missing dependencies:
# For development - sync all dependencies
uv sync
# Or install individual packages if needed
uv pip install termcolor cryptography
Connection issues:
# Use debug mode for detailed troubleshooting
ssl-checkup --debug example.com
# Test insecure connections for self-signed certificates
ssl-checkup --insecure your-internal-server.com
Installation issues:
# Ensure Python 3.11+
python --version
# Install with pipx (recommended for CLI tools)
pipx install ssl-checkup
# If pipx isn't available, install it first
pip install --user pipx
pipx ensurepath
# Alternative: Install with pip (may cause conflicts)
pip install ssl-checkup
# Or use uv for development
uv sync && uv run ssl-checkup example.com
# Force reinstall if needed
pipx reinstall ssl-checkup
License
GPL-3.0 License - see LICENSE file for details.
Project maintained by BaDxKaRMa. Contributions welcome!
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ssl_checkup-1.0.1.tar.gz.
File metadata
- Download URL: ssl_checkup-1.0.1.tar.gz
- Upload date:
- Size: 36.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.11.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
35b260f91a634d494d04c785ad0abf3f9e6101eafb90bb60d542823a0b9d5200
|
|
| MD5 |
12d814ce3252b3bcc5df254ff6b86acf
|
|
| BLAKE2b-256 |
5a8ba702b2d0c91d7dac5b14a0e95438eaa2e0d2b95f66632db63b9e565ea2d9
|
File details
Details for the file ssl_checkup-1.0.1-py3-none-any.whl.
File metadata
- Download URL: ssl_checkup-1.0.1-py3-none-any.whl
- Upload date:
- Size: 25.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.11.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
47635750afd0e2571bc2012c7cc7c348b457c79a3a83d24195257780491da85d
|
|
| MD5 |
26325d9e1deac989fe5dee74e6dd071e
|
|
| BLAKE2b-256 |
399e21e32849bbd592fa2851ba8c6a7938f7f429e1b923baa8c45cd7cbc268ce
|