Python certificate chain resolver
Resolve and obtain the complete certificate chain from the leaf, intermediate(s) to the root of a x509 certificate using the CLI or the python API.
The library provides an easy to use API to access each property of a certificate chain and the important metadata of a certificate. The library also exposes a CLI for resolving and inspecting certificate chains from the command line.
Support
- PKCS7, PEM and DER formats
- LetsEncrypt certificates
- Including the root certificate using the system CA bundle or custom bundle
- Python2 (but not for much longer..)
Installation
$ pip install cert-chain-resolver
CLI Usage
For more options and examples see the read the docs or pass the --help flag.
The bundle gets written to stdout and the chain information to stderr.
from source:
$ python -m cert_chain_resolver.cli --include-root certificate.crt > bundle.crt
$ cat certificate.crt | python -m cert_chain_resolver.cli --include-root > bundle.crt
from PIP
$ cert_chain_resolver --include-root certificate.crt > bundle.crt
1. <Cert common_name="github.com" subject="CN=github.com,O=GitHub\, Inc.,L=San Francisco,ST=California,C=US" issuer="CN=DigiCert SHA2 High Assurance Server CA,OU=www.digicert.com,O=DigiCert Inc,C=US">
2. <Cert common_name="DigiCert SHA2 High Assurance Server CA" subject="CN=DigiCert SHA2 High Assurance Server CA,OU=www.digicert.com,O=DigiCert Inc,C=US" issuer="CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US">
3. <Cert common_name="DigiCert High Assurance EV Root CA" subject="CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US" issuer="CN=DigiCert High Assurance EV Root CA,OU=www.digicert.com,O=DigiCert Inc,C=US">
Python API
Make sure to read the documentation for more examples and options.
from cert_chain_resolver.api import resolve
with open('cert.pem', 'rb') as f:
fb = f.read()
chain = resolve(fb)
>>>
for cert in chain:
print(cert)
print(cert.export()) # Export the certificate in PEM format
<Cert common_name="cert-chain-resolver.remcokoopmans.com" subject="CN=cert-chain-resolver.remcokoopmans.com" issuer="CN=R3,O=Let's Encrypt,C=US">
"-----BEGIN CERTIFICATE-----...."
<Cert common_name="R3" subject="CN=R3,O=Let's Encrypt,C=US" issuer="CN=DST Root CA X3,O=Digital Signature Trust Co.">
"-----BEGIN CERTIFICATE-----...."
<Cert common_name="DST Root CA X3" subject="CN=DST Root CA X3,O=Digital Signature Trust Co." issuer="CN=DST Root CA X3,O=Digital Signature Trust Co.">
"-----BEGIN CERTIFICATE-----...."
Dependencies
- cryptography
After cloning the repository
Install dependencies
$ make
Development
bootstrap
$ make
Testing
Unit testing
$ make tests
Re-run tests on file changes:
$ make tests TEST_ARGS="-- -f"
Formatting
$ make format
Metadata
Release files for cert-chain-resolver 1.4.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| cert_chain_resolver-1.4.1.tar.gz | 18.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| cert_chain_resolver-1.4.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 42.2 kB
Release files / cert_chain_resolver-1.4.1.tar.gz
| Download URL | cert_chain_resolver-1.4.1.tar.gz |
|---|---|
| Size | 18.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
995358207109005a0a32d2f1fad59e244bdb8bb07a70b51ea6f5566b7cb2ab45
|
|
BLAKE2b-256 checksum How to use checksums |
1f77a8c1feafddf0d10de5637193f9cdaf8b4ef89b064f4817357e6766ff8a09
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Release files / cert_chain_resolver-1.4.1-py3-none-any.whl
| Download URL | cert_chain_resolver-1.4.1-py3-none-any.whl |
|---|---|
| Size | 23.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
79bbfdac3a90f5eea1fc40b9b0e736ab3414f759ceafa94d6d4adb887bf055b4
|
|
BLAKE2b-256 checksum How to use checksums |
791e4ff60ca8892c510f74a2aee7e5efa2ba6c9914f743d666c8a226957c2ccf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|