Search tools

Certificate Decoder

Read an X.509 certificate or CSR: subject, issuer, dates, SANs and fingerprint.

Tokens & Certificates

Certificate

Read, not trusted

  • Certificates and CSRs: PEM or DER: subject, issuer, serial number, validity dates, subject alternative names, key type and size, signature algorithm and fingerprints.
  • Dates are only dates: The page says whether today is within the certificate’s declared dates. Trust, revocation and whether it fits a website need checks this page does not make.
  • Private keys stay closed: A private key block is named and not read further. Nothing is sent anywhere: no OCSP, no CRL, no issuer is contacted.

Frequently asked questions

Which fingerprint do browsers show?

Usually SHA-256 over the whole certificate, written in hex pairs. Both SHA-256 and the older SHA-1 fingerprints are shown here.

Can I open a .crt or .cer file?

Yes: PEM text and binary DER files both work, and a file with several blocks lists each one.