certchain

Retired — functionality merged into urlrecon.

retired 2026-05-31

This tool has moved

certchain was a Python CLI for Certificate Transparency queries, TLS chain validation, and local certificate-file inspection. Every feature has been absorbed into urlrecon as the certchain subcommand — with several enhancements:

Migration

# Old (certchain)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- certchain
certchain query cyberramen.com
certchain validate cyberramen.com
certchain inspect /etc/ssl/cert.pem

# New (urlrecon certchain)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- urlrecon
urlrecon certchain query cyberramen.com --limit 20
urlrecon certchain query cyberramen.com --include-expired --format json
urlrecon certchain validate cyberramen.com
urlrecon certchain validate cyberramen.com:8443
urlrecon certchain inspect /etc/ssl/cert.pem --format markdown
urlrecon certchain batch domains.txt

Why retired?

certchain duplicated urlrecon's TLS handshake stack and its crt.sh client. Both tools already used rustls + x509-parser; merging them means urlrecon owns the whole TLS-and-certificate posture surface, and operators install one binary instead of two.

Important caveat: certchain's Python build had OCSP / CRL revocation checks. urlrecon's certchain does NOT yet verify revocation — that's planned for a follow-up session (needs an OCSP responder client + cache). CT monitoring (the long-running monitor subcommand) is also deferred because it fits a daemon mode, not a one-shot CLI.

→ Go to urlrecon