Cert Lifetime Lint — TLS validity caps 200/100/47

Finds the renewal settings in your repo that outlive the public TLS cap: 200 days since 15 March 2026, 100 days from 15 March 2027, 47 days from 15 March 2029.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Finds the renewal settings in your repo that outlive the public TLS cap: 200 days since 15 March 2026, 100 days from 15 March 2027, 47 days from 15 March 2029.

Hosted certificate-expiry monitoring is $25-29 a month.

Buy the full version — $29

Questions people ask

What does Cert Lifetime Lint actually do?

It reads the certificate settings written in your repository - cert-manager duration and renewBefore, Terraform validity_period_hours, cfssl and step-ca expiry, openssl -days, keytool -validity, Ansible not_after, Traefik certificatesDuration and renewal cron schedules - and marks every value that a public certificate authority will no longer issue, with the replacement line beside it.

Who is it for?

Platform, SRE and DevOps engineers who own the renewal path: the person whose pager fires when an ACME order is refused or a certificate expires at 3am. If you maintain cert-manager Certificates, Terraform tls resources, a cfssl or step-ca profile, or the crontab that runs certbot, this reads your files.

Why will a free SSL checker not do this?

Free checkers connect to a live host and report the certificate that is already serving traffic. That certificate is valid, so they stay silent. The failure lives in the config you have not applied yet - a duration of 8760h that the CA will refuse at the next issuance. Nothing that probes a live port can see it.

What is free and what needs a licence?

Free covers one whole file: open a manifest, run the check, and all 16 rules report every over-cap line with its fix and severity. Nothing is watermarked, timed or locked after N runs. The licence changes the scope only - every file in the repository at once, a dated exported report, and JSON output for CI.

What would this cost otherwise?

Hosted certificate-expiry monitoring runs about $25 to $29 a month, and it still only watches certificates that are already live. Auditing renewal config by hand means grepping every repository each time the cap steps down, which it does on 15 March 2027 and again on 15 March 2029. This is $29 once.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool