#!/usr/bin/env python3
"""SSL/TLS configuration snapshot for authorized hosts."""

from __future__ import annotations

import argparse
import socket
import ssl
from datetime import datetime, timezone


def inspect(host: str, port: int) -> None:
    context = ssl.create_default_context()
    with socket.create_connection((host, port), timeout=10) as raw:
        with context.wrap_socket(raw, server_hostname=host) as tls:
            cert = tls.getpeercert()
            not_after = datetime.strptime(cert["notAfter"], "%b %d %H:%M:%S %Y %Z").replace(tzinfo=timezone.utc)
            print(f"host: {host}:{port}")
            print(f"protocol: {tls.version()}")
            print(f"cipher: {tls.cipher()}")
            print(f"subject: {cert.get('subject')}")
            print(f"issuer: {cert.get('issuer')}")
            print(f"expires_utc: {not_after.isoformat()}")
            print(f"days_until_expiry: {(not_after - datetime.now(timezone.utc)).days}")
            print(f"san: {cert.get('subjectAltName', [])}")


def main() -> int:
    parser = argparse.ArgumentParser(description="Inspect an authorized host's TLS certificate and negotiated settings.")
    parser.add_argument("host")
    parser.add_argument("--port", type=int, default=443)
    args = parser.parse_args()
    inspect(args.host, args.port)
    return 0


if __name__ == "__main__":
    raise SystemExit(main())
