certchain
Retired — functionality merged into urlrecon.
retired 2026-05-31This tool has moved
certchain was a Python CLI for Certificate Transparency queries,
TLS chain validation, and local certificate-file inspection.
Every feature has been absorbed into
urlrecon as the
certchain subcommand — with several enhancements:
- Full chain walk + issuer reputation tagging — every cert in the chain is matched against a curated known-CA list (Let's Encrypt, DigiCert, ZeroSSL, GTS, Sectigo, Entrust, …). Self-signed and unknown CAs surface prominently.
- SAN explosion warning — single cert covering more than 20 SANs flagged as a finding (broad asset exposure).
- Pre-certificate heuristic in CT results (catches the IETF 7-day pre-cert pattern).
- crt.sh + censys.io operator pivot URLs emitted with every report.
- Cert + SPKI SHA-256 fingerprints per cert in the chain (HPKP / pin-rotation workflows).
- Markdown report output ready for IR write-ups.
--include-expired+--limit Ndefaults — Python returned the full crt.sh dump which was overwhelming for popular domains.
Migration
# Old (certchain)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- certchain
certchain query cyberramen.com
certchain validate cyberramen.com
certchain inspect /etc/ssl/cert.pem
# New (urlrecon certchain)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- urlrecon
urlrecon certchain query cyberramen.com --limit 20
urlrecon certchain query cyberramen.com --include-expired --format json
urlrecon certchain validate cyberramen.com
urlrecon certchain validate cyberramen.com:8443
urlrecon certchain inspect /etc/ssl/cert.pem --format markdown
urlrecon certchain batch domains.txt
Why retired?
certchain duplicated urlrecon's TLS handshake stack and its crt.sh client. Both tools already used rustls + x509-parser; merging them means urlrecon owns the whole TLS-and-certificate posture surface, and operators install one binary instead of two.
Important caveat: certchain's Python build had
OCSP / CRL revocation checks. urlrecon's certchain
does NOT yet verify revocation — that's planned for a follow-up
session (needs an OCSP responder client + cache). CT monitoring
(the long-running monitor subcommand) is also
deferred because it fits a daemon mode, not a one-shot CLI.