SSL Certificate Decoder (X.509)

Paste a PEM certificate, a whole chain or the Base64 of a DER file to read who it was issued to, by whom and until when, with its alternative names, key, extensions and fingerprints.

Loading tool…

About the Certificate Decoder

An X.509 certificate (RFC 5280) binds a public key to a name and is signed by an issuer. It is an ASN.1 structure encoded in DER; a PEM file is that DER in Base64 between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. The decoder parses the DER with its own ASN.1 reader and shows what openssl x509 -text -noout would: subject and issuer distinguished names, serial number, version, the validity period with the days remaining, the signature algorithm, and the public key — RSA modulus size and exponent, elliptic curve name, or Ed25519.

Most of what matters in a TLS certificate is in its extensions. Subject Alternative Name lists the host names and IP addresses the certificate is valid for; browsers ignore the common name. Basic Constraints says whether it is a CA, Key Usage and Extended Key Usage what the key may do, Authority Information Access and CRL Distribution Points where to check revocation and fetch the issuer, and the SCT list proves the certificate was logged in Certificate Transparency. Extensions the tool does not know are listed by object identifier with their critical flag.

The SHA-256 and SHA-1 fingerprints are hashes of the whole DER certificate, computed with the Web Crypto API. When several certificates are pasted, the tool shows how they chain and checks each signature with the public key of its issuer, and a self-signed certificate with its own key. It does not tell whether the chain ends at a root your browser trusts, nor whether a certificate was revoked. Certificate signing requests and public keys are decoded too; private keys are recognised, never decoded, and nothing leaves your browser.

How to use it

  1. Paste the PEM text, or click “Open file” to load a .pem, .crt, .cer or .der file.
  2. Check the validity chip and the alternative names.
  3. Read the key, the signature and the extensions.
  4. Copy a fingerprint, the public key or any value with its Copy button.

Frequently asked questions

How do I get the certificate of a website?
Run openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null and paste the output: every certificate block in it is decoded. In a browser, click the padlock, open the certificate and export it as PEM.
Is it safe to paste my certificate here?
Yes. A certificate is public: your server sends it to every visitor. It is decoded in your browser and not transmitted. The private key is the secret part and is never needed to read a certificate.
What is the difference between PEM, DER, CRT and CER?
DER is the binary encoding; PEM is the same bytes in Base64 with BEGIN and END lines. .crt and .cer are only file extensions and can hold either. This tool reads both.
Why does the browser reject a certificate that shows as valid here?
Valid here means the current date is inside the validity period. A browser also needs a host name that matches a Subject Alternative Name, a chain to a trusted root, and a certificate that is not revoked.

Related tools