Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ssl-certificate-expiry-date-checker — Scans SSL/TLS certificates for expiry dates, issuer details, and OCSP status. Sends notifications via webhook, Telegram, or Slack. Supports proxy per domain and generates detailed logs. | Kitploit
Tools/GitHubGitHub/password123456/ssl-certificate-expiry-date-checker
Vulnerability ScannersConfiguration AuditingNetwork SecurityCryptographyLog Analysis
GitHubpassword123456/ssl-certificate-expiry-date-checker

ssl-certificate-expiry-date-checker

Scans SSL/TLS certificates for expiry dates, issuer details, and OCSP status. Sends notifications via webhook, Telegram, or Slack. Supports proxy per domain and generates detailed logs.

View Repository
122613 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ssl_certificate_expiry_date_checker

made-with-python Python Versions Hits

  • Find out which cerificate will expire and need to renew.
  • Find various information from scan result (expire date, issuer, signature, serial number...)
  • If you are ssl cerificate manager in your organization, collect the list from your coworker, teams, and check the expire date of the certificates.
  • custom notify when SSL certificates are about to expire with a detail result (WEBHOOK, Telegram-Bot, Slack...)
  • The difference from other similar tools, optionally choose to use proxy by domain. for example, there's a system in the restricted private enviroment network and have to scan, you may have to use proxy.
  • In the configuraion you can set the proxy ip/port and can set which domains must pass through the proxy system in the list.txt.
  • If you have a various log analyzer, you can collect logs and do what you want to more.

Features

  • scan ssl_certificate and get information (before_date, after_date, issuer, issuer_hash, serial, signatures)
  • set pass through the proxy or not by domain.
  • ocsp valid check by domain.
  • verify ssl_certificates that will be expire within set days.
  • create custom logs and can query.

And...

  • Please let me know if any changes are required or if additional features are needed.
  • If you find this helpful, please consider giving it a "star"🌟 to support further improvements.

Documentation

# pip install pyOpenSSL

# vim list.txt
..set the configuration...

Usage

# python .\main.py 

# SSL certificate scan start
(1) [Proxy],  scan_ok, www.google.com
(2) [Proxy],  scan_ok, account.google.com
(3) [Proxy],  scan_ok, www.github.com
(4) [Proxy],  scan_ok, www.naver.com
(5) [Normal], scan_ok, es.stackoverflow.com
(6) [Failed], scan_failed, devnote_wrong.in - Domain Lookup Failed. 
(7) [Failed], scan_failed, not_exits_domain.in - Domain Lookup Failed. 
(8) [Normal], scan_ok, www.youtube.com
(9) [Proxy],  scan_ok, developer.mozilla.org

# scan completed
- F:\code\pythonProject\pysslaudit2/output/2022-04-20-pysslaudit.log 

# Certificate will expire within 90 days.
(1) [Not Valid in 61-days], [2022-06-20 02:26:06], www.google.com, @@dev1-team
(2) [Not Valid in 61-days], [2022-06-20 01:19:43], account.google.com, @@dev1-team
(3) [Not Valid in 49-days], [2022-06-08 12:00:00], www.naver.com, @@dev2-team
(4) [Not Valid in 76-days], [2022-07-05 13:17:41], es.stackoverflow.com, @@dev2-team
(5) [Not Valid in 61-days], [2022-06-20 01:19:43], www.youtube.com, @Mephisto.act3

# Certificate Scan Failed.
(1) [Errno 11001] getaddrinfo failed, devnote_wrong.in, @@dev2-team
(2) [Errno 11001] getaddrinfo failed, not_exits_domain.in, @baal.act5

# OCSP Scan result.
(1) OCSPResponseStatus.MALFORMED_REQUEST, www.google.com
(2) OCSPResponseStatus.MALFORMED_REQUEST, account.google.com
(3) OCSPCertStatus.GOOD, www.github.com
(4) OCSPCertStatus.GOOD, www.naver.com
(5) OCSPResponseStatus.UNAUTHORIZED, es.stackoverflow.com
(6) OCSPResponseStatus.MALFORMED_REQUEST, www.youtube.com
(7) OCSPCertStatus.GOOD, developer.mozilla.org
Download Tool