ATTEST
read the certificate

Read a certificate before you trust it.

An offline reader for X.509 certificates and chains: it parses the DER itself, grades the key, the hash, the dates and the names, and verifies no signature — which it tells you plainly.

Python 3.10+PyQt6 network never436 testsMIT

Why

Nobody reads the certificate. It is a wall of base64 that a browser either accepts or does not, and when something is wrong the error names a symptom rather than a cause.

Everything that matters is in there in the open: how long it lives, how strong the key is, what hash signed it, which names it covers, and whether the chain you were handed actually joins up.

What it draws. The chain ladder — a rung per certificate, tinted by the worst finding on it, with the join drawn solid gold where the issuer matches and dashed red where it does not.
Attest reading two samples

The reader on two of its bundled samples.

What it checks

SignalWhat trips it
Datesexpired, not yet valid, or expiring within a month
Lifetimelonger than the 398 days public TLS now allows
SignatureMD5 or SHA-1 rather than SHA-256 or better
KeyRSA under 2048 bits, or a sound curve
Namesno subjectAltName, or a wildcard and what it covers
ConstraintsCA:TRUE on a leaf, missing key usage
Chainwhether each issuer really matches the next subject

The honest part

Attest verifies no signature, checks no revocation, consults no trust store, and cannot tell you a live server holds the matching private key. It reads what the certificate says about itself. It also needs no cryptography library: the ASN.1 DER parser is its own.

Install

git clone https://github.com/at0m-b0mb/Attest-X509.git
cd Attest-X509
python3 -m pip install -r requirements.txt

python3 -m attest                      # the window
python3 -m attest samples/             # the command line
python3 -m pytest -q                   # 436 tests

The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.

One of seven readers