> SSLPing needs less than 5 seconds to check your server and tell you what's wrong with your SSL/TLS security.
So I guess it used OpenSSL to figure out what was wrong with people's certificates. Not sure what it used that relied on internals so heavily it was hard to upgrade, or if the public interface just changed a lot.
Even with that, seems there was multiple issues that "prevented" ("made it harder than justifiable" rather) the author from keeping the project up, not just regarding OpenSSL.
More: Enter a list of (sub-) domains and get informed via email when "SSL things" change (for better or for worst), or your https certificate is about to expire.
Less: No fancy pansy "report"
Personally I prefer https://hardenize.com nowadays, over ssllabs for these kind of queries.
(Hardenize founder, previously also SSL Labs founder.)
> tell you what's wrong
Actually node.js is using openssl under the hood... SSLPing implemented a partial SSL implementation to quickly test support for SSL versions and cyphers, but used node.js native libs too. Newer node.js versions weren't able to get an SSL certificate out of a SSL v3 only server, for instance. Which didn't allow to test for expiration, etc...
But yes, there were multiple issues indeed
It didn't just check if a certificate is valid now, but whether the certificate, intermediary, CA (or anything in the chain) is about to expire soon.
It might have needed to poke deeper into OpenSSL than regular uses.
Perhaps their service also tested for deprecated ciphers/tls versions?
This is a problem for all testing tools that rely on OpenSSL. If you follow this direction, you typically need to use at least two OpenSSL versions, one new to test modern features and one very old to test obsolete features.
I know you appreciate the issue to its fullest like no one else! Cheers