Open source · Security & Privacy

TLS Certificate Inventory

Inventory certificate files, names, issuers and validity windows offline.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Certificate incidents are boring and they are all the same. Something expired that nobody was watching. A renewal was staged early and deployed before its notBefore. A bundle went out without its intermediate. A wildcard did not cover the host somebody assumed it covered. A 2015-era appliance is still serving a SHA-1 certificate with a 1024-bit key.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

npm install github:edilec/tls-certificate-inventory

Read the result

This installs the public GitHub source; tls-certificate-inventory is not published to npm.

Where this check stops

What it is good for: knowing what is on disk, catching the expiry before the pager does, finding the bundle that lost its intermediate, and proving that nobody left a 1024-bit key in the fleet.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.