Skip to content
Esc

Certificate decoder

Decode an SSL certificate, chain or CSR.

Try

Decoded

Paste a certificate to see what’s in it. Nothing is fetched: links inside it are shown as text.

About this tool

Runs in
your browser
Your input sent to our servers
Nothing
Kept on this device
nothing

More in the privacy policy.

How to use it

  1. 01Paste a certificate (-----BEGIN CERTIFICATE-----), several in a row for a chain, or a certificate request; or open a .pem, .crt, .cer, .der or .csr file, or drop one on the page. Or pick one under Try.
  2. 02Read each certificate’s card: who it’s for and who issued it, how long it’s valid, its names, key, extensions and fingerprints. In a chain, each card says whether its signature checks out against the next certificate’s key.
  3. 03Copy any value, a certificate’s PEM on its own, or the whole summary as text.

Related tools

Questions

Does it check whether the certificate is trusted or revoked?

No. It shows what’s inside and checks signatures between the certificates you paste, with your browser’s own cryptography. Trust depends on the root certificates your system or browser holds, and revocation on the issuer’s OCSP or CRL service; checking either means sending requests, which this page doesn’t do. The OCSP and CRL addresses are shown as text.

What does “checked against the next certificate” mean?

In a chain, each certificate is signed with the key of the one after it: the leaf by an intermediate, the intermediate by a root. The page checks each signature against the next certificate’s public key. A root signs itself. If your browser can’t do a signature’s algorithm, the card names the algorithm and says it can’t check. RSA-PSS signatures are checked; a public key restricted to RSA-PSS may not be accepted by your browser (Chrome doesn’t accept it), and then the card says so. If the next certificate’s name doesn’t match this certificate’s issuer, the chain is in the wrong order or a certificate is missing.

Can I paste a private key?

Don’t. The page recognises a private key and doesn’t decode it, but a private key shouldn’t be pasted into any website. If one was in use and you pasted it somewhere, replace it.

What is the SHA-256 fingerprint?

A hash of the whole certificate, the same value browsers show in their certificate viewer and openssl x509 -fingerprint -sha256 prints. Two certificates with the same fingerprint are the same certificate.

Is my certificate sent anywhere?

No. It’s decoded in your browser, and a file you open is read there too. It isn’t sent to our servers, put into the page address or saved.