{"repo":"zmap/zlint","free":true,"listed":false,"github":"https://github.com/zmap/zlint","clone":"git clone https://github.com/zmap/zlint.git","description":"X.509 Certificate Linter focused on Web PKI standards and requirements.","language":"Go","stars":444,"topics":["linter","x509"],"license":"Apache-2.0","category":"dev-tools","readme_excerpt":"ZLint ===== ZLint is a X.509 certificate linter written in Go that checks for consistency with standards (e.g. [RFC 5280]) and other relevant PKI requirements (e.g. [CA/Browser Forum Baseline Requirements][BR v1.4.8]). It can be used as a command line tool or as a library integrated into CA software. [RFC 5280]: https://www.ietf.org/rfc/rfc5280.txt [BR v1.4.8]: https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.4.8.pdf Requirements ------------ ZLint requires Go 1.16.x or newer be installed. The command line setup instructions assume the go command is in your $PATH . Lint Sources ------------ Historically ZLint was focused on only [RFC 5280] and [v1.4.8][BR v1.4.8] of the [CA/Browser Forum baseline requirements][BRs]. A detailed list of the original BR coverage can be found [in this spreadsheet][Coverage Spreadsheet]. More recently ZLint has been restructured to make it easier to add lints based on other sources. While not complete, presently ZLint has lints sourced from: [CA/Browser Forum EV SSL Certificate Guidelines][CABF EV] [ETSI ESI] [Mozilla's PKI policy][MozPolicy] [Apple's CT policy][AppleCT] Various RFCs (e.g. [RFC 6818], [RFC 4055], [RFC 8399]) By default ZLint will apply applicable lints from all sources but consumers may also customize which lints are used by including/exclduing specific sources. [BRs]: https://cabforum.org/baseline-requirements-documents/ [Coverage Spreadsheet]: https://docs.google.com/spreadsheets/d/1fNJfGZ-G2tcv6Fv6ejP-ZygZzaplgqvA9","default_branch":null,"files":null,"tree":[],"storefront":"/r/zmap","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zmap/zlint/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}