Skip to content

X.509 Certificate Decoder

Decodes an SSL/TLS certificate to show the names it covers, when it expires, who issued it, and every extension inside it.

Your certificate stays on this device

This tool runs entirely inside your web browser. Your certificate is processed on your own device and is never sent to our servers. How this works

Paste a certificate above, or click Example. Nothing is uploaded: it is read here in your browser.

X.509 Certificate Decoder is a free tool that reads an SSL/TLS certificate and explains what is inside it: the host names it covers, when it expires, who issued it, how strong the key is, and what every extension means. Paste a PEM block or open a .crt, .cer or binary .der file. Decoding happens entirely in your browser, so the certificate is never sent to our servers.

How to decode a certificate

  1. Paste the certificate, including the -----BEGIN CERTIFICATE----- and END lines. A whole chain is fine.
  2. Read the summary: who it was issued to and by, the dates, the serial number and the key.
  3. Check the list of names it covers, and type a host name to test whether that host is included.
  4. Look through the extensions for key usage, revocation addresses and anything marked critical.

Getting a certificate to paste

From a live site, run openssl s_client -connect example.com:443 -showcerts and copy the blocks it prints. In a browser, click the padlock in the address bar, view the certificate and export it. On a server, the file is usually named something like fullchain.pem or example.com.crt.

What the dates mean

A certificate is valid only between its two dates, checked against the clock on the device reading it. This page compares them with your own clock, so a device with the wrong time will see a certificate as expired or not yet valid when everyone else sees it working. Public certificates now last at most about 13 months, so an expiry date far in the future usually means an internal or self-signed certificate.

Names, and why the common name no longer counts

Browsers decide whether a certificate covers a site by reading its subject alternative names, not its common name. The common name is a leftover from before that list existed, and a certificate that names a host only there will be rejected. A wildcard such as *.example.com covers exactly one label: it matcheswww.example.com, but neither example.com itself nor a.b.example.com.

Decoding is not verifying

This tool shows what a certificate claims. It does not prove the certificate is genuine or trusted, which would mean following the chain up to a root certificate your device already trusts and checking every signature on the way — something a web page cannot do. A self-signed certificate decodes perfectly and is still untrusted.

Fingerprints and pinning

The SHA-256 fingerprint is a hash of the whole certificate, used to compare one against a known-good copy. The public key pin is a hash of the key alone, which survives renewal as long as the same key is reused — that is why pinning uses it rather than the fingerprint. To hash other data, use theHash Generator, and to check a request before a certificate exists, use theCSR Decoder.

Troubleshooting

Frequently asked questions

Is it safe to paste a certificate here?

Yes, and a certificate is public anyway: every visitor to a website receives it. It is decoded in your browser and never sent to our servers. A private key is different — never paste one anywhere, including here.

Does this check that the certificate is valid and trusted?

No. It shows what the certificate says, including whether today falls inside its dates. Proving a certificate is genuine means following the chain up to a root your device already trusts, which a web page cannot do.

Can I paste a whole chain?

Yes. Paste every block and each certificate is decoded in turn, in the order you pasted it. That order matters: a server should send its own certificate first, then each issuer above it.

My certificate is a .der or .cer file, not text.

Use Open file and pick it. A binary certificate is converted to PEM text so you can read it, and decoded the same way.

What is the difference between the common name and the SANs?

Browsers check only the subject alternative names. The common name is a leftover from before SANs existed; a certificate with a name in the common name alone will be rejected by every current browser.

Last updated

Missing a feature, or need a tool we don’t have? Suggest it.