certigo Commands Reference

Friendly certificate dump and verify tool from Square — a practical alternative to raw openssl x509 / s_client for day-to-day inspection.

📦 Installation

brew install certigo
go install github.com/square/certigo@latest

📄 Dump certificates

PEM / chain files

certigo dump cert.pem
certigo dump --json cert.pem

PKCS#12

certigo dump -f PKCS12 -p 'secret' bundle.p12

🌐 Connect to a host

certigo connect example.com:443
certigo connect --verify example.com:443
certigo connect -n api.example.com 10.0.0.5:443
certigo connect --json example.com:443

-n sets the expected hostname / SNI when connecting by IP.

✅ Verify a chain

certigo verify -n www.example.com chain.pem
certigo verify -n www.example.com --ca /path/ca-bundle.pem chain.pem

📬 STARTTLS

certigo connect -t smtp mail.example.com:25
certigo connect -t mysql db.example.com:3306
certigo connect -t ldap ldap.example.com:389
certigo connect -t postgres db.example.com:5432

Supported protocols include ldap, mysql, postgres, smtp, and ftp.

🔗 See Also

Docs: github.com/square/certigo