Is there a reminder service out there that specializes in your long-term expiring things? I'm not sure what would be different about it than a regular calendar, but it seems like many of us need something that makes this easier.
Is there a reminder service out there that specializes in your long-term expiring things? I'm not sure what would be different about it than a regular calendar, but it seems like many of us need something that makes this easier.
At larger companies a lot of the issue isn't literally generating reminders, it is making sure they're sent to the correct people/departments and are actioned by anyone.
For example you sometimes have reminders sent to ex-employees, or sent to a mailing list and everyone assuming everyone else is going to action it. Or the reminder gets ping-ponged between multiple managers via email with nobody either able or willing to deal with it.
None of these are tech' issues, and they don't have technology solutions as a consequence. So whenever I see an embarrassing expired cert, I don't assume technical malfunction, I assume political malfunction.
tcp_client = TCPSocket.new(domain, 443)
ssl_client = OpenSSL::SSL::SSLSocket.new(tcp_client)
ssl_client.hostname = domain
ssl_client.connect
cert = OpenSSL::X509::Certificate.new(ssl_client.peer_cert)
ssl_client.sysclose
tcp_client.close
certprops = OpenSSL::X509::Name.new(cert.issuer).to_a
issuer = certprops.select { |name, data, type| name == "O" }.first[1]
results = {
valid_on: cert.not_before.utc,
valid_until: cert.not_after.utc,
issuer: issuer,
days_left: (cert.not_after.utc - Time.now.utc).to_i / (24 * 60 * 60),
}It would be nice if they prompted you to 'add to calendar' when you are creating certs.
That would actually be a really _awesome_ integration of ACME client software with CalDAV [0] and other ticketing software APIs like Jira: set up calendar events and/or tickets with increasing priority to verify that the certificate is updated.
import ssl
import OpenSSL
from datetime import datetime
cert = ssl.get_server_certificate((www.google.com, 443))
x509 = OpenSSL.crypto.load_certificate(OpenSSL.crypto.FILETYPE_PEM, cert)
expiry_dt = datetime.strptime(x509.get_notAfter()[:8].decode('utf-8'), '%Y%m%d')Also, no need for python:
echo | openssl s_client -connect google.com:443 -servername google.com -showcerts 2>&1 | openssl x509 -text -noout | grep "Not After" | cut -d : -f 2- | xargs -I {} date -d "{}" +%Y%m%d
I appreciate the sentiment but I think it's fine for them to just say "we examined our processes, found out what led to the issue, and have modified procedures". I worry a detailed post mortem would just throw specific folks under the bus (most likely some low level employee who isn't actually the root cause)
if free, simple and it checks your TLS settings too