Skip to content

CSR Decoder

Decodes a certificate signing request to show the names and details it asks for, and checks that its signature matches the key inside it.

Your request stays on this device

This tool runs entirely inside your web browser. Your request is processed on your own device and is never sent to our servers. How this works

Paste a CSR above, or click Example. Check it says what you expect before sending it to a certificate authority — the details cannot be changed afterwards without starting again.

CSR Decoder is a free tool that reads a certificate signing request and shows exactly what it asks for: the common name, the organisation details, the host names, and the public key. It also checks the request’s own signature, so you can be sure it matches its key before you send it to a certificate authority. Everything is read in your browser and nothing is uploaded.

How to check a CSR

  1. Paste the request, including the -----BEGIN CERTIFICATE REQUEST----- line, or open a .csr file.
  2. Look at the signature banner first: it confirms the request matches the private key it was made with.
  3. Check the common name and the list of names requested, and read them character by character — a typo here becomes a certificate you cannot use.
  4. Check the key algorithm and size are what your certificate authority expects.

What a CSR actually is

When you ask for a certificate, you generate a private key and a request. The request holds your public key and the details you want on the certificate, and it is signed with the matching private key. The private key never leaves your server: that is the whole design. The authority checks the signature, verifies who you are by its own means, and issues a certificate binding your public key to the names it has confirmed.

Why the signature check is worth doing

A CSR is signed by the private key belonging to the public key inside it. That proves the two match and that nothing has been altered since it was created — a request damaged by a bad copy-and-paste fails the check. Every certificate authority performs this check and rejects the request if it fails, so catching it here saves a slow round trip. This page performs the same check with your browser’s own cryptography.

Ask for every name you need

Browsers read the subject alternative names and ignore the common name entirely. Most authorities copy the common name into that list for you, but if you need several host names on one certificate you must ask for all of them: they cannot be added afterwards without issuing a new certificate. Generate a request with several names usingopenssl req -new -addext "subjectAltName=DNS:example.com,DNS:www.example.com".

What you ask for is not always what you get

A CSR is a request, not an instruction. The authority decides what the certificate says: it normally keeps the common name, the alternative names and the public key, and replaces most other extensions with its own policies, revocation addresses and key usage settings. Organisation details are kept only for certificates where the authority has verified the organisation. Once the certificate comes back, read it with theX.509 Certificate Decoder to see what was actually issued.

Troubleshooting

Frequently asked questions

Is it safe to paste a CSR here?

Yes. A CSR holds only public information and is meant to be sent to a certificate authority. It is decoded in your browser and never sent to our servers. The private key it was made with is a separate file — never paste that anywhere.

What does the signature check tell me?

A CSR is signed by the private key belonging to the public key inside it. If that check passes, the pair match and nothing has been altered since it was created. If it fails, a certificate authority will reject the request, so generate it again.

Why does it warn that no names were requested?

Browsers check the subject alternative names and ignore the common name. Most authorities will copy the common name into a SAN for you, but asking for the names you want explicitly avoids any doubt about what you will get back.

Will the certificate say exactly what my CSR asks for?

Not necessarily. The authority decides: it usually keeps the common name, the SANs and the public key, and replaces most other extensions with its own. Treat the request as what you asked for, not what you will receive.

Last updated

Missing a feature, or need a tool we don’t have? Suggest it.