TLS Certificate Auditor avatar

TLS Certificate Auditor

Pricing

Pay per usage

Go to Apify Store
TLS Certificate Auditor

TLS Certificate Auditor

Connect to a public host over TLS and audit its certificate posture: expiry and days remaining, hostname/SAN matching, chain completeness and trust, protocol, cipher, and key strength. Returns a score, grade, issues, and recommendations.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Sanskar Jaiswal

Sanskar Jaiswal

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

3 days ago

Last modified

Share

Connects to any public host over TLS and audits its certificate posture in one API call. Checks validity dates and days until expiry, hostname and Subject Alternative Name matching, chain completeness and trust status, negotiated protocol and cipher, and public key strength. Returns a readiness score, letter grade, issues, and recommendations as structured JSON.

Use cases

  • DevOps and platform teams monitoring certificate expiry across endpoints and catching renewals that silently fail
  • Security teams auditing chain completeness, self-signed certificates, weak keys, and deprecated TLS protocol versions
  • Site migration QA verifying that every endpoint serves the right certificate for its hostname after a cutover
  • Agency consultants running recurring certificate posture checks across client domains
  • CI pipelines gating deployments on certificate regressions

Input

FieldTypeDefaultDescription
startUrlstring(required)Public HTTPS URL or bare hostname to audit. The actor opens one TLS connection to this host on port 443 (or the URL port) and inspects the served certificate chain.
timeoutSecondsinteger10TLS connection timeout, from 3 to 30 seconds.
expiryWarningDaysinteger30Flag the certificate as expiring soon when it expires within this many days.

Output

One dataset item per run:

FieldTypeDescription
inputUrlstringURL as provided in the input.
normalizedInputUrlstring or nullURL after scheme normalization and validation.
hoststringHostname that was audited.
portinteger or nullTLS port used (443 or the URL port).
okbooleanWhether the audit completed without a connection or validation error.
checkedAtstringISO 8601 timestamp of the check.
connectedbooleanWhether the TLS connection was established.
authorizedbooleanWhether the served chain is trusted by standard root stores.
authorizationErrorstring or nullNode trust validation error, when the chain is not authorized.
subjectCommonNamestring or nullLeaf certificate subject common name.
issuerCommonNamestring or nullLeaf certificate issuer common name.
issuerOrganizationstring or nullLeaf certificate issuer organization.
subjectAltNamesarrayDNS Subject Alternative Names on the leaf certificate.
hostnameMatchbooleanWhether the audited hostname matches the certificate SAN list or CN.
matchedCertificateNamestring or nullThe SAN or CN entry that matched.
validFromstring or nullCertificate validity start, ISO 8601.
validTostring or nullCertificate expiry, ISO 8601.
daysUntilExpiryinteger or nullWhole days from now until expiry (negative when expired).
expiryStatusstringOne of: valid, expiring-soon, expired, not-yet-valid, unknown.
expiredbooleanWhether the certificate is currently expired.
expiringSoonbooleanWhether the certificate expires within the configured warning window.
fingerprint256string or nullSHA-256 fingerprint of the leaf certificate.
serialNumberstring or nullLeaf certificate serial number.
keyTypestring or nullPublic key type (RSA or EC).
keyBitsinteger or nullPublic key size in bits.
weakKeybooleanWhether the public key is below the recommended strength for its type.
protocolstring or nullNegotiated TLS protocol version (for example TLSv1.3).
cipherNamestring or nullNegotiated cipher suite.
cipherVersionstring or nullCipher version reported by the TLS stack.
weakCipherbooleanWhether the negotiated cipher is a legacy or weak suite (NULL, RC4, 3DES, CBC-only).
chainDepthintegerNumber of certificates in the served chain.
chainSubjectsarrayCN or organization of each certificate in the chain.
hasSelfSignedRootbooleanWhether the served chain ends in a self-signed root certificate.
selfSignedLeafbooleanWhether the leaf certificate itself is self-signed.
chainLikelyIncompletebooleanWhether the chain appears to be missing intermediate certificates.
scoreintegerCertificate posture score from 0 to 100.
gradestringLetter grade from A+ to F.
issuesarrayConcrete problems found.
recommendationsarrayActionable fixes.
errorstring or nullError message when the audit could not complete.

Example input

{
"startUrl": "https://www.wikipedia.org/",
"timeoutSeconds": 10,
"expiryWarningDays": 30
}

Example output

{
"host": "www.wikipedia.org",
"port": 443,
"ok": true,
"authorized": true,
"subjectCommonName": "*.wikipedia.org",
"issuerCommonName": "Sectigo RSA Domain Validation Secure Server CA",
"subjectAltNames": ["*.wikipedia.org", "wikipedia.org"],
"hostnameMatch": true,
"matchedCertificateName": "*.wikipedia.org",
"daysUntilExpiry": 200,
"expiryStatus": "valid",
"protocol": "TLSv1.3",
"cipherName": "TLS_AES_256_GCM_SHA384",
"keyType": "RSA",
"keyBits": 2048,
"weakKey": false,
"weakCipher": false,
"chainDepth": 3,
"score": 100,
"grade": "A+",
"issues": [],
"recommendations": [
"Certificate posture looks good. Re-run daily or weekly to catch renewals that silently fail."
],
"error": null
}

Security

  • Connects to public hosts only; URLs with credentials are rejected.
  • Private IPv4, private IPv6, and loopback targets are blocked, hostnames are DNS-resolved, and resolutions to private ranges are rejected (SSRF defense).
  • One TLS connection per run to the validated host; no HTTP page content is fetched, no cookies are stored, no JavaScript is executed.
  • Trust validation is performed and reported (authorized flag and trust error); deliberately broken certificates remain inspectable so the audit can explain exactly what is wrong.

Pricing

EventPrice
Actor start$0.005 per run
Host audited$0.01 per result

A typical single-host audit costs $0.015.

FAQ

Why would a certificate that browsers trust still fail the trust check? The actor validates the served chain against standard root stores the way a strict client does. If the server omits an intermediate certificate, some browsers can fill the gap from cached intermediates or built-in knowledge while strict clients cannot. The audit reports the incomplete chain so it can be fixed at the origin.

Does the actor fetch the website content? No. It opens a TLS connection and inspects the handshake and served certificate chain only, then closes the connection.

What counts as a weak key? RSA keys below 2048 bits and EC keys below 256 bits. Anything below the browser baseline (RSA 2048 or EC P-256) is flagged.

How should I use the expiry warning window? Set expiryWarningDays to match how long a renewal takes in your workflow (issuance, validation, CDN propagation). The default of 30 days fits ACME-automated setups; manual workflows may want 60 or more.