Cert Decode
/install cert-decode
Cert Decode
Parse and display human-readable details from X.509 PEM certificates using openssl.
Input
- PEM certificate content (text starting with
-----BEGIN CERTIFICATE-----) pasted directly, OR - Path to a
.pemor.crtfile, OR - Hostname to fetch the live certificate from (e.g.,
example.com)
Output
- Subject (CN, O, OU, C)
- Issuer (CA name, organization)
- Validity: Not Before / Not After (expiry date)
- Serial number
- Subject Alternative Names (SANs)
- Public key algorithm and size
- Signature algorithm
- Whether the cert is expired or expiring soon
Instructions
-
Determine input type: pasted PEM text, file path, or hostname.
-
From pasted PEM text: Write the PEM content to a temp file, then:
echo "PEM_CONTENT" | openssl x509 -text -nooutOr use process substitution if available.
-
From a file path:
openssl x509 -text -noout -in /path/to/cert.pem -
From a live hostname (port 443):
echo | openssl s_client -connect HOSTNAME:443 -servername HOSTNAME 2>/dev/null | openssl x509 -text -noout -
Extract and present key fields from the
openssl x509 -textoutput in a clean, readable format:- Subject: parse
Subject:line - Issuer: parse
Issuer:line - Valid From: parse
Not Before: - Valid Until: parse
Not After : - Serial: parse
Serial Number: - SANs: parse
X509v3 Subject Alternative Name:block for allDNS:andIP Address:entries - Key: parse
Public Key Algorithm:and key size (e.g.,RSA Public-Key: (2048 bit)) - Signature Algorithm: parse
Signature Algorithm:
- Subject: parse
-
Calculate whether the certificate is:
- Already expired (Not After is in the past)
- Expiring within 30 days (warn the user)
- Valid (show days remaining)
-
If
opensslis not found, tell the user:"This skill requires
openssl. Install with:brew install openssl(macOS) orsudo apt install openssl(Linux)."
Examples
From file:
Command: openssl x509 -text -noout -in /etc/ssl/cert.pem
From hostname:
Command: echo | openssl s_client -connect github.com:443 -servername github.com 2>/dev/null | openssl x509 -text -noout
Sample parsed output:
Subject: CN=github.com, O=GitHub, Inc., C=US
Issuer: CN=DigiCert TLS Hybrid ECC SHA384 2020 CA1, O=DigiCert Inc, C=US
Valid From: 2024-03-07
Valid Until: 2025-03-06 ⚠ Expires in 14 days
Serial: 0a:bc:12:...
SANs: github.com, www.github.com
Key: EC 256-bit (prime256v1)
Signature: ecdsa-with-SHA384
Error Handling
opensslnot found → tell user to install it- Input is not valid PEM → openssl will error with
unable to load certificate; tell user the input does not appear to be a valid PEM certificate - Hostname unreachable →
openssl s_clientwill fail; report connection error and suggest checking the hostname or network - DER format instead of PEM → tell user to convert first with:
openssl x509 -inform DER -in cert.der -out cert.pem - Certificate chain (multiple certs) → only the first cert is parsed; inform user if they need a specific cert from the chain
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install cert-decode - 安装完成后,直接呼叫该 Skill 的名称或使用
/cert-decode触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
Cert Decode 是什么?
Decode and inspect X.509 SSL/TLS certificates. Use when the user asks to read a certificate, parse a PEM file, check certificate expiry, inspect a TLS cert,... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 140 次。
如何安装 Cert Decode?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install cert-decode」即可一键安装,无需额外配置。
Cert Decode 是免费的吗?
是的,Cert Decode 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Cert Decode 支持哪些平台?
Cert Decode 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Cert Decode?
由 Omar Hernandez(@ohernandez-dev-blossom)开发并维护,当前版本 v1.0.0。