寻求可模拟即将过期SSL证书的在线服务
Great question! I’ve faced this exact scenario when building and testing certificate expiration monitoring tools—having a reliable endpoint with a certificate nearing expiration (like 5 days out) is way more useful than just an already expired one for validating alerting and renewal logic.
Unfortunately, most public test platforms (including the one you mentioned) focus on expired, invalid, or misconfigured certificates rather than ones approaching expiration. Maintaining dynamically updating short-lived certificates for public use is tricky, since they’d need constant renewal. But there are totally feasible ways to get what you need:
Spin up your own test endpoint
This is the most reliable approach. You can generate a 5-day valid SSL certificate in minutes usingopenssl, then host a simple HTTPS server to act as your test interface. Here’s a quick breakdown of the steps:- Generate a private key:
openssl genrsa -out test.key 2048 - Create a certificate signing request (CSR):
openssl req -new -key test.key -out test.csr - Sign the CSR with a 5-day validity period:
openssl x509 -req -days 5 -in test.csr -signkey test.key -out test.crt - Launch a basic HTTPS server (Python makes this easy):
python -m http.server 443 --cert test.crt --key test.key
Now you have a local HTTPS endpoint with a certificate that expires in 5 days—perfect for your testing needs.
- Generate a private key:
Use API mocking tools with custom certificates
Tools like WireMock or Postman’s mock servers let you upload custom SSL certificates. Generate that 5-day cert as above, upload it to your mock server, and you can create a dedicated test interface that behaves exactly like a real service with an expiring certificate.
This approach gives you full control over the certificate’s expiration timeline, and you don’t have to rely on external services that might not offer this specific use case.
内容的提问来源于stack exchange,提问作者ThomasArdal

