tls_certificate_info
Retrieve and parse a host's TLS certificate to get subject, issuer, validity, SANs, key type, and chain validation in one handshake.
Instructions
Retrieve and parse the TLS certificate a host in scope presents: subject, issuer, validity, SANs, key type, and whether the chain validates. Makes one TLS handshake and sends no application data. SANs are labelled with their own scope verdict. Cost: 1 quota unit, 1-10 seconds.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | Hostname in scope. | |
| port | No | TLS port. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| host | Yes | ||
| port | Yes | ||
| cipher | No | ||
| issuer | No | ||
| expired | No | ||
| subject | No | ||
| not_after | No | ||
| pinned_ip | Yes | ||
| not_before | No | ||
| public_key | No | ||
| self_signed | No | ||
| chain_length | No | ||
| verification | No | ||
| serial_number | No | ||
| chain_subjects | No | ||
| days_until_expiry | No | ||
| negotiated_protocol | No | ||
| signature_algorithm | No | ||
| subject_alternative_names | No |