# cmr1-ssl-validator

> Scan and validate SSL certificate(s)

Latest version **0.4.2** (published 2020-03-10) · MIT license · 0 weekly downloads

## Install

```sh
npm install cmr1-ssl-validator
pnpm add cmr1-ssl-validator
yarn add cmr1-ssl-validator
bun add cmr1-ssl-validator
```

Provides the command `ssl-validator`.

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support; pre 1.0.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 0.4.2 |
| Published | 2020-03-10 |
| First published | 2017-05-02 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=6.x |
| Dependencies | 4 |
| Unpacked size | 27.6 KB |
| Known vulnerabilities | 0 (+1 in 1 direct dependencies) |
| Install scripts | no |
| GitHub stars | 0 |
| Author | Charlie McClung |
| Maintainers | cmr1 |
| Keywords | cmr1, ssl, letsencrypt |

## Links

- npm: https://www.npmjs.com/package/cmr1-ssl-validator
- Repository: https://github.com/cmr1/node-ssl-validator
- Homepage: https://github.com/cmr1/node-ssl-validator#readme
- Issues: https://github.com/cmr1/node-ssl-validator/issues
- npm.io page: https://npm.io/package/cmr1-ssl-validator

## Dependencies (4)

- [async](https://npm.io/package/async.md) ^2.4.0
- [aws-sdk](https://npm.io/package/aws-sdk.md) ^2.331.0
- [cmr1-cli](https://npm.io/package/cmr1-cli.md) ^0.1.13
- [slack-node](https://npm.io/package/slack-node.md) ^0.1.8

## Recent versions

- 0.4.2 (latest) — 2020-03-10
- 0.4.1 — 2019-07-26
- 0.4.0 — 2019-04-08
- 0.3.2 — 2018-10-10
- 0.3.0 — 2017-11-28
- 0.2.4 — 2017-11-18
- 0.2.3 — 2017-05-04
- 0.2.2 — 2017-05-03
- 0.2.1 — 2017-05-03
- 0.2.0 — 2017-05-03
- 0.1.7 — 2017-05-03
- 0.1.6 — 2017-05-03
- 0.1.5 — 2017-05-03
- 0.1.4 — 2017-05-02
- 0.1.3 — 2017-05-02
- … 5 more at https://npm.io/package/cmr1-ssl-validator/versions

## README

[![npm version](https://badge.fury.io/js/cmr1-ssl-validator.svg)](https://www.npmjs.com/package/cmr1-ssl-validator)
[![build status](https://travis-ci.org/cmr1/node-ssl-validator.svg?branch=master)](https://travis-ci.org/cmr1/node-ssl-validator)

# node-ssl-validator
Scan and validate SSL certificates

### Table of contents
- [CLI](#cli)
  - [Install](#install-globally)
  - [Help](#show-help)
  - [Basic example](#basic-cli-example)
  - [Advanced example](#advanced-cli-example)  
- [Module](#module)
  - [Install](#install-locally)
  - [Help](#show-help)
  - [Basic example](#basic-code-example)
  - [Advanced example](#advanced-code-example)  
- [Hooks](#hooks)
  - [Hook arguments](#hook-arguments)
  - [Success example](#success-example)
  - [Failure example](#failure-example)

## CLI

#### Install globally:
```bash
npm install -g cmr1-ssl-validator
```

#### Show help:
```bash
ssl-validator --help
```

#### Basic cli example:
```bash
# Scan & validate current directory
ssl-validator 

# Scan & validate default Let's Encrypt directory
ssl-validator /etc/letsencrypt/live --recursive

# Scan & validate default dehydrated directory
ssl-validator /etc/dehydrated/certs --recursive
```

#### Advanced cli example:
```bash
ssl-validator \
  # Use recursive flag to group certs by directory
  --recursive \

  # Scan & validate default dehydrated directory
  --directory /etc/dehydrated/certs \          
  
  # Provide cert & key file regular expressions
  --certfile "^(fullchain|cert).pem$" \
  --keyfile "^privkey.pem$" \

  # Provide expiration period in days
  --time 30 \

  # Provide a slack webhook URL for notifications
  --slack https://hooks.slack.com/services/foo/bar/foobar \

  # Provide an executable hook to trigger with invalid certificate info
  --hook /usr/bin/foo-bar \

  # Validate certificates stored on AWS Certificate Manager (ACM)
  --acm
```

[Back to Top](#node-ssl-validator)

## Module

#### Install locally:
```bash
npm install --save cmr1-ssl-validator
```

#### Basic code example:
```javascript
// Require cmr1-ssl-validator module
const SslValidator = require('cmr1-ssl-validator');

// Create a new validator with default options
const validator = new SslValidator();

// Run validator with default options
validator.run(err => {
  if (err) {
    // Something went wrong
    validator.error(err);
  } else {
    // All finished
    validator.log('Finished.');
  }
});
```

#### Advanced code example:
```javascript
// Require cmr1-ssl-validator module
const SslValidator = require('cmr1-ssl-validator');

// Create a new validator with default options
const validator = new SslValidator({
  // Use recursive flag to group certs by directory
  recursive: true,

  // Scan & validate default dehydrated directory
  directory: '/etc/dehydrated/certs',

  // Provide cert & key file regular expressions
  certfile: '^(fullchain|cert).pem$',
  keyfile: '^privkey.pem$',

  // Provide expiration period in days
  time: 30,

  // Provide a slack webhook URL for notifications
  slack: 'https://hooks.slack.com/services/foo/bar/foobar',

  // Provide an executable hook to trigger with invalid certificate info
  hook: '/usr/bin/foo-bar',

  // Validate certificates stored on AWS Certificate Manager (ACM)
  acm: true
});

// Run validator with default options
validator.run(err => {
  if (err) {
    // Something went wrong
    validator.error(err);
  } else {
    // All finished
    validator.log('Finished.');
  }
});
```

[Back to Top](#node-ssl-validator)

## Hooks
An executable can be called after completion with information about failure(s).

#### Hook arguments:
```bash
/path/to/hook EXIT_CODE [DOMAIN_LIST]
```

- `EXIT_CODE` is the exit status of the validator (`0` or `1`)
- `DOMAIN_LIST` a list of invalid domains, grouped by certificate
  - Domains are joined by `,`
  - Groups are joined by `;`
  - **Example:** `abc.co,www.abc.co;xyz.co,www.xyz.co`
    - *Two certs: `abc.co` & `xyz.co`, both with alternate domain name: `www.`*

#### Success example:
```bash
/path/to/hook 0
```

#### Failure example:
```bash
/path/to/hook 1 abc.co,www.abc.co;xyz.co,www.xyz.co
```

[Back to Top](#node-ssl-validator)

---
_Source: https://npm.io/package/cmr1-ssl-validator · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
