certdays.sh somedomain.com 14
If the certificate for somedomain.com is valid less then 14 days, it will fail:
Fixed now. Thanks.
We can use this command in CI pipeline or setup a cron job to monitor it.
~ ~/certdays.sh google.com 14
date: illegal time format
usage: date [-jnRu] [-d dst] [-r seconds] [-t west] [-
v[+|-]val[ymwdHMS]] ...
[-f fmt date | [[[mm]dd]HH]MM[[cc]yy][.ss]]
[+format]
google.com: -18568
-n Lasts longer then 14 days?
NO!!!!!!!!!!!!!!I have put it into a Github repo now and put the link into the post. Does that work for you?
I know I can't throw stones in this particular greenhouse :)
But still, multi-million companies should surely be able to handle that.
If I was an engineer changing a test regarding SSL certs expiry time, after a change, I'd test it with a cert that has expired, about to expire and one far in the future. Manually or automated doesn't really matter, but test your changes after you've done them. Really basic stuff.
Because the comment said something like: There was a bug, so they didn't have a test, why don't they? And I replied: Tests can have bugs too.
Validity Not Before 11/2/2020, 12:00:00 AM (Greenwich Mean Time)
Validity Not After 11/9/2021, 11:59:59 PM (Greenwich Mean Time)
command_name check_certificate
command_line $USER1$/check_http -H $ARG1$ -p $ARG2$ -4 -S -C 21 -t 20 --sni
this won't warn about certificate name mismatches though-C 21 means: Check the certificate. Warn if less than 21 days and critical when expired.
Maybe someone could get fired for this or does it have more to do with Microsoft's stock/public image?
openssl s_client -connect github.githubassets.com:443
verify error:num=10:certificate has expired
notAfter=Nov 2 12:00;00 2020 GMT
That's today about 22min ago from time of writing, not 1 day ago.Depending on what your browser still has in its cache, github.com will be in various states of degradation.