About the Certificate Decoder
An X.509 certificate (RFC 5280) binds a public key to a name and is signed by an issuer. It is an ASN.1 structure encoded in DER; a PEM file is that DER in Base64 between -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. The decoder parses the DER with its own ASN.1 reader and shows what openssl x509 -text -noout would: subject and issuer distinguished names, serial number, version, the validity period with the days remaining, the signature algorithm, and the public key — RSA modulus size and exponent, elliptic curve name, or Ed25519.
Most of what matters in a TLS certificate is in its extensions. Subject Alternative Name lists the host names and IP addresses the certificate is valid for; browsers ignore the common name. Basic Constraints says whether it is a CA, Key Usage and Extended Key Usage what the key may do, Authority Information Access and CRL Distribution Points where to check revocation and fetch the issuer, and the SCT list proves the certificate was logged in Certificate Transparency. Extensions the tool does not know are listed by object identifier with their critical flag.
The SHA-256 and SHA-1 fingerprints are hashes of the whole DER certificate, computed with the Web Crypto API. When several certificates are pasted, the tool shows how they chain and checks each signature with the public key of its issuer, and a self-signed certificate with its own key. It does not tell whether the chain ends at a root your browser trusts, nor whether a certificate was revoked. Certificate signing requests and public keys are decoded too; private keys are recognised, never decoded, and nothing leaves your browser.
How to use it
- Paste the PEM text, or click “Open file” to load a .pem, .crt, .cer or .der file.
- Check the validity chip and the alternative names.
- Read the key, the signature and the extensions.
- Copy a fingerprint, the public key or any value with its Copy button.
Frequently asked questions
How do I get the certificate of a website?
openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null and paste the output: every certificate block in it is decoded. In a browser, click the padlock, open the certificate and export it as PEM.Is it safe to paste my certificate here?
What is the difference between PEM, DER, CRT and CER?
.crt and .cer are only file extensions and can hold either. This tool reads both.