Code & Scripts

TLS Cert Expiry Scanner

A read-only script that scans your fleet's listening TLS ports, extracts every cert in use, and produces a dated report ranking each by days-to-expiry, SANs, issuer, and chain health. Catches the self-signed cert your predecessor installed on the internal API three years ago before it breaks prod on a Sunday.

$ tar -tzf tls-cert-expiry-scanner.tar.gz
  • tls_scan.py — Main scanner; standard library only, no external dependencies
  • hosts.example.txt — Sample hosts file showing the host:port input format with commented service examples
  • report.example.csv — Pre-generated sample output showing all status labels (OK, WARN, EXPIRED, ERROR) across 12 realistic rows — know what you're reading before you run it
  • runbook.md — Step-by-step guide: prerequisites, flags, scheduling, reading the report, known limitations
  • README.md — One-page overview with 3-command quick start
$17

one-time purchase

Instant download after purchase
📧Download link sent to your email
🔄7-day download access
14-day money-back guarantee
View refund policy

## goes-well-with

From the same shelf

## not-ready-to-buy

Take the field notes instead

One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.