In the web security ecosystem, there is still a lack of tools that combine execution speed, result clarity and full automation of processes related to HTTPS and HSTS diagnostics. Classic solutions deliver only partial functionality or require complex integrations. In response to these limitations, HEXSSL-CLI was created, an official command line tool that introduces a new level of quality to the analysis of certificates and HSTS headers. It is lightweight, fast and ready to run locally as well as in CI/CD pipelines. It was designed to immediately replace collections of scripts, manual tests and external services that do not fit modern automation processes.
HEXSSL-CLI has been released as a package on PyPI and GitHub, enabling rapid installation and seamless integration with DevOps tooling. The first release is not an experiment. It is a fully fledged component of the HEXSSL ecosystem, intended to support system administrators, security teams, developers and infrastructure operators in their daily operations related to certificates and HTTPS configuration.
Table of Contents
ToggleHEXSSL-CLI is a tool designed for practical diagnostics. It analyzes domain configurations, checks the presence and correctness of security headers, evaluates redirect paths and verifies compliance with Chrome HSTS Preload requirements. Unlike generic tools, it does not focus on conceptual analysis. Instead, it provides precise, targeted diagnostics related to transport security and SSL certificates.
Modern software delivery requires simple and predictable tools. Administrators need to quickly verify whether server configuration changes comply with organizational policies. DevSecOps teams require the ability to validate domains directly in pipelines. HEXSSL-CLI was created to simplify these activities and to provide a consistent diagnostic workflow independent of the environment.
HEXSSL-CLI analyzes the complete set of security headers related to HSTS. It verifies correctness, policy length, absence of syntax errors and support for parameters such as includeSubDomains and preload. This makes it possible to quickly detect configurations that lead to loss of an A rating in audit tools or expose users to downgrade attacks.
The tool checks whether a domain meets the requirements for submission to the HSTS Preload list. Until now, this process was often performed manually or via a browser. The CLI automates it in a repeatable and environment independent manner.
The redirect checker module examines the complete user transition path from HTTP to HTTPS. This makes it easy to identify loops, excessive numbers of steps or incorrect sequences that prevent proper handling of secure connections.
The CLI allows analysis of not only the main domain, but also subpages and subdomains. This enables audits similar to those performed in internal scripts of large organizations, where monitoring complex application structures is required.
HEXSSL-CLI generates a detailed report containing a final grade and a clear result structure. The report is well suited for archiving in CI/CD systems, attaching to issue trackers or presenting as part of an infrastructure security review.
HEXSSL-CLI was prepared to operate in a repeatable manner on any platform that supports Python. The tool core is based on clean code, without dependencies that complicate maintenance. The project structure was designed with future expansion in mind. The modular architecture allows additional test types to be added, and the layer responsible for presenting results is separated from diagnostic logic. As a result, the CLI is not a one time utility but a foundation for future versions that will introduce further analyses and integrations.
Organizations increasingly shift transport security control to the pipeline level. This is where configuration errors most often originate. Domain validation during application deployment minimizes the risk of production issues and enables automatic enforcement of security policies. HEXSSL-CLI provides repeatability and predictability of results, giving teams the ability to react immediately to incorrect configurations.
Integration with CI/CD is a natural next step. HEXSSL-CLI can be included as part of test stages in GitHub Actions, GitLab CI, Jenkins and Azure DevOps. Test results are clear and unambiguous, allowing pipelines to be automatically halted when issues are detected.
The first release is a foundation that will be extended in subsequent stages. The roadmap includes, among others:
Each subsequent step is intended to bring the CLI closer to becoming an essential tool in the daily workflow of administrators and security teams.
HEXSSL-CLI represents an important step toward building a comprehensive HEXSSL tooling ecosystem. It is a tool based on practical experience and real administrative needs, combining precise diagnostics, clear reporting and automation at every stage of the deployment process. It introduces to the Polish and European market a tool that until now was reserved for the largest global security service providers. For administrators, this means fewer manual tasks. For DevOps teams, greater control over deployment quality. For organizations, a higher level of security.
HEXSSL-CLI is the first tool that raises the technical level of HEXSSL and opens the door to further projects in the areas of security automation, AI and certificate analytics.
Do you have questions related to HEXSSL-CLI? Visit the project page: https://github.com/hexssl/hexssl-cli or contact us: Contact.