An offline reader for X.509 certificates and chains: it parses the DER itself, grades the key, the hash, the dates and the names, and verifies no signature — which it tells you plainly.
Nobody reads the certificate. It is a wall of base64 that a browser either accepts or does not, and when something is wrong the error names a symptom rather than a cause.
Everything that matters is in there in the open: how long it lives, how strong the key is, what hash signed it, which names it covers, and whether the chain you were handed actually joins up.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| Dates | expired, not yet valid, or expiring within a month |
| Lifetime | longer than the 398 days public TLS now allows |
| Signature | MD5 or SHA-1 rather than SHA-256 or better |
| Key | RSA under 2048 bits, or a sound curve |
| Names | no subjectAltName, or a wildcard and what it covers |
| Constraints | CA:TRUE on a leaf, missing key usage |
| Chain | whether each issuer really matches the next subject |
Attest verifies no signature, checks no revocation, consults no trust store, and cannot tell you a live server holds the matching private key. It reads what the certificate says about itself. It also needs no cryptography library: the ASN.1 DER parser is its own.
git clone https://github.com/at0m-b0mb/Attest-X509.git
cd Attest-X509
python3 -m pip install -r requirements.txt
python3 -m attest # the window
python3 -m attest samples/ # the command line
python3 -m pytest -q # 436 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.