Claude Code skills · updated 2026-10-03

TLS cert validity skill for Claude Code — 200/100/47-day caps, openssl -days

Flags cert scripts, Terraform and cert-manager values that break under SC-081v3

tls-cert-validity-check - findings on the bundled example

On one 22-line shell script it printed 8 findings (5 errors, 3 warnings) from 12 rules, each with file:line, what breaks, the date and the fix.

Get it on Whop - $12 onceGet it on Gumroad

Who it's for

For DevOps and platform engineers who issue TLS certificates from shell scripts, Terraform or cert-manager and own the renewal pipeline.

What breaks, and when

Since 2026-03-15 a public TLS certificate may not exceed 200 days, and on 2027-03-15 the cap falls to 100 days (SC-081v3): openssl -days 365 is refused or truncated.

What it printed on the bundled example

== TLS Cert Lifetime Lint — 8 findings (5 errors, 3 warnings) in 1 file · 12 rules
  WARN  issue-edge-cert.sh:8  [stale-max-lifetime-claim]
        This text still states the old 397, 398 or 825-day maximum. The public TLS maximum has been 200 days since 2026-03-15, becomes 100 days on 2027-03-15 and 47 days on 2029-03-15 (SC-081v3), so anyone planning a renewal from this line plans it wrong.
        fix: State the current cap and the two dated step-downs.
  ERROR issue-edge-cert.sh:9  [openssl-days-over-200]
        openssl -days is over 200. Since 2026-03-15 a publicly trusted TLS certificate may not exceed 200 days (CA/Browser Forum ballot SC-081v3), and the cap falls to 100 days on 2027-03-15. A public CA will refuse or truncate this request.
        fix: Use -days 90 and let ACME renew, or keep this key for an internal CA only.
  ERROR issue-edge-cert.sh:9  [sha1-signature]
        SHA-1 signing is requested. Public CAs stopped signing SHA-1 certificates in 2016 and browsers reject the chain outright, so this certificate cannot be used on a public endpoint.

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check whether our certificate scripts and cert-manager config will break with the new shorter TLS certificate validity periods? Don't edit anything yet.". Needs Node 16+.

unzip tls-cert-validity-check.zip -d ~/.claude/skills/

Ask Claude

“Can you check whether our certificate scripts and cert-manager config will break with the new shorter TLS certificate validity periods? Don't edit anything yet.”

What it does not do

No network calls; it checks the settings written in your repo, not the certificate a server is serving.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

No network calls; it checks the settings written in your repo, not the certificate a server is serving.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check whether our certificate scripts and cert-manager config will break with the new shorter TLS certificate validity periods? Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.