TLS Cert Lifetime Lint - SC-081v3 renewal check

Finds the 12 settings that break when public TLS certificates fall to 100 days on 2027-03-15: openssl -days, Terraform, cert-manager, late expiry alerts, HPKP, TLS 1.0/1.1, SHA-1, RSA-1024.

Get the complete version $29

This page is the working piece. The full pack has everything below.

Finds the 12 settings that break when public TLS certificates fall to 100 days on 2027-03-15: openssl -days, Terraform, cert-manager, late expiry alerts, HPKP, TLS 1.0/1.1, SHA-1, RSA-1024.

A certificate lifecycle management platform starts at $50,000-$100,000 a year plus $1-$5 per certificate (Keyfactor Command, 2026 vendor pricing).

Buy the full version — $29

Questions people ask

What does TLS Cert Lifetime Lint actually do?

It reads certificate configuration as text and flags settings that the CA/Browser Forum SC-081v3 schedule has already broken or will break on a named date. It checks openssl -days values, Terraform validity_period_hours, cert-manager duration, expiry alert thresholds, HPKP headers, TLS 1.0/1.1, SHA-1 signing and RSA keys under 2048 bits, and reports the line number, the cap that applies and the value to use instead.

Who is this for?

Platform, SRE and DevOps engineers who issue publicly trusted TLS certificates from infrastructure as code - Terraform, cert-manager, Ansible, shell scripts around openssl - and who own the renewal that pages someone at 3am. It is aimed at teams that still have annual or six-monthly renewal habits written into repositories and runbooks.

Why not just ask a chatbot or run an SSL scanner?

An online SSL scanner tests a certificate that is already serving traffic, so it finds the problem after deployment. A chatbot answers from training data and still repeats the retired 398-day maximum. This reads the configuration in the repository before anything is issued, and carries the dated schedule - 200 days from 2026-03-15, 100 from 2027-03-15, 47 from 2029-03-15 - as fixed rules rather than recall.

What is free and what needs a licence?

Free covers one file completely: open a config, run the check, and you see every one of the 12 findings with its line number, severity and replacement value. Nothing is blurred or limited by a trial counter. A licence adds the next job - scanning the whole repository, exporting the findings as CSV, JSON or HTML, and writing CI JSON so a pipeline fails before a bad certificate ships.

How does the price compare to the alternative?

A certificate lifecycle management platform is the usual answer to this problem and it starts around $50,000 to $100,000 a year plus $1 to $5 per certificate at 2026 vendor pricing. This is $29 once, with a 7-day full refund. It does not manage certificates - it stops the configuration mistakes that make a renewal fail in the first place.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool