network · Command reference

qzx checkSslCertificate

What it does

Inspects certificate dates, hostname coverage, and trust-chain validation

Canonical command: checkSslCertificate

Accepted aliases: None

Case-sensitive: no

Included in the published package

Available in PyPI 0.2.2.0.2. This page documents the 0.2.2.0.2 alpha development checkout.

Safety and effects

Read-only under the current classification

No documented dry-run parameter

No native program invocation in the current classification

May use the network

No inherent elevation requirement

This safety classification was reviewed against implementation digest sha256:feaa2f067638dc709e3b87686d52d1950e30286a7cb2b0e83e8af62e690ef068 on 2026-07-24.

Exact syntax

qzx checkSslCertificate <host> [port] --json

Parameters

NameTypeRequiredDefaultDescription
hoststrYesNot declaredHostname of the server to check (for example, example.com)
portintNo443TLS port number

Input examples

qzx checkSslCertificate example.com

Inspect and validate example.com's certificate

qzx checkSslCertificate expired.badssl.com 443

Inspect an expired certificate while reporting the trust failure

For the complete structured payload, add --json: qzx checkSslCertificate <host> [port] --json

Representative output example

This illustrative JSON is derived from the current implementation-backed result contract. It shows what the command can return without claiming a recorded execution; values vary with inputs, host, permissions, and optional tools.

Example command: qzx checkSslCertificate example.com --json

{
    "success": true,
    "message": "Inspects certificate dates, hostname coverage, and trust-chain validation. In this illustrative example, the command completed successfully.",
    "chain_trusted": true,
    "cipher_bits": 256,
    "cipher_protocol": "TLSv1.3",
    "cipher_suite": "TLS_AES_256_GCM_SHA384",
    "dates": {
        "not_before": "2026-06-01T00:00:00Z",
        "not_after": "2026-09-01T23:59:59Z"
    },
    "days_remaining": 38,
    "host": "example.com",
    "hostname_match": true,
    "is_expired": false,
    "is_started": true,
    "is_valid": true,
    "issuer": "CN=Example Trust Services",
    "port": 443,
    "ssl_version": "TLSv1.3",
    "subject": "CN=example.com",
    "subject_alt_names": [
        "example.com",
        "www.example.com"
    ],
    "verification_error": null
}
View the JSON result contract
{
    "$schema": "https://json-schema.org/draft/2020-12/schema",
    "type": "object",
    "required": [
        "success",
        "message"
    ],
    "properties": {
        "success": {
            "type": "boolean"
        },
        "message": {
            "type": "string"
        },
        "chain_trusted": [],
        "cipher_bits": [],
        "cipher_protocol": [],
        "cipher_suite": [],
        "dates": {
            "type": "object",
            "properties": {
                "not_before": {
                    "type": "null"
                },
                "not_after": {
                    "type": "null"
                }
            },
            "additionalProperties": true
        },
        "days_remaining": [],
        "error": {
            "type": "string"
        },
        "error_code": {
            "type": "string"
        },
        "host": [],
        "hostname_match": [],
        "is_expired": [],
        "is_started": [],
        "is_valid": [],
        "issuer": [],
        "port": [],
        "ssl_version": [],
        "subject": [],
        "subject_alt_names": [],
        "verification_error": []
    },
    "additionalProperties": true
}

Errors and limits

The public contract requires success=false and a descriptive message on failure. This catalog does not yet declare a command-specific error taxonomy; inspect the result and do not invent error codes.

QZX is alpha software. Optional dependencies, permissions, and host capabilities can change the result.

Evidence workflow: requires an authorized endpoint or reviewed fixture.

Evidence and provenance

Documentation channel
Development documentation 0.2.2.0.2 · main · sha256:319b16857a87636ebc3b89734cc040a737bb56194464fca33ce73bdae2043096
Availability
0.2.2.0.2 or earlier

Keep exploring

These commands also belong to the network category. Compare them to choose the operation that best fits your task.

Explore all QZX commands