SSL Certificate Decoder
Parse X.509 PEM/DER certificates locally to inspect subject, issuer, validity, public key, SANs, fingerprints and common extensions.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is SSL Certificate Decoder?
An X.509 certificate contains a subject, issuer, public key, validity period, SANs, key usages and extensions. Use this local parser to inspect PEM or DER material while diagnosing HTTPS deployment, confirming a domain/IP name and checking one certificate in a chain. Parsing decodes a file only: it does not connect to a server, query OCSP/CRL or build a chain, so it cannot by itself establish trust, revocation status or suitability for a live hostname.
How to Use
- Paste or import a PEM/DER certificate
- Inspect subject, issuer, SANs, validity, public key and extensions
- Use the complete chain, actual host name and client trust store to assess deployment status
FAQ
- Does an unexpired certificate always work?
- No. Also check SAN matching, matching private key, intermediate chain, algorithms, client trust and revocation.
- Can this tell whether the certificate is revoked?
- No. Revocation needs OCSP or CRL status; offline decoding has no live revocation information.
- Why are there multiple fingerprints?
- Different hash algorithms produce different display fingerprints. Both sides must use the same algorithm and the same DER certificate bytes when comparing.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Key Format ConverterConvert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.CSR Parser & Signature CheckerParse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.
Last updated 2026-10-09