Actively poll a list of domains to pull certificate and determine if it's self-signed. This is a proof of concept script. See internal script notes for license and TODO. Run script with -h for options help. Users must provide list, exclusion, and cache file paths.
Note: Why do this yourself if Project Sonar is scanning all the things? See Project Sonar at Rapid7 and have a look at my sonar-ssc-harvester project.