SSL Certificate Decoder

Parse X.509 PEM/DER certificates locally to inspect subject, issuer, validity, public key, SANs, fingerprints and common extensions.

Privacy: all processing happens locally in your browser. Your input never leaves your device.

What is SSL Certificate Decoder?

An X.509 certificate contains a subject, issuer, public key, validity period, SANs, key usages and extensions. Use this local parser to inspect PEM or DER material while diagnosing HTTPS deployment, confirming a domain/IP name and checking one certificate in a chain. Parsing decodes a file only: it does not connect to a server, query OCSP/CRL or build a chain, so it cannot by itself establish trust, revocation status or suitability for a live hostname.

How to Use

  1. Paste or import a PEM/DER certificate
  2. Inspect subject, issuer, SANs, validity, public key and extensions
  3. Use the complete chain, actual host name and client trust store to assess deployment status

FAQ

Does an unexpired certificate always work?
No. Also check SAN matching, matching private key, intermediate chain, algorithms, client trust and revocation.
Can this tell whether the certificate is revoked?
No. Revocation needs OCSP or CRL status; offline decoding has no live revocation information.
Why are there multiple fingerprints?
Different hash algorithms produce different display fingerprints. Both sides must use the same algorithm and the same DER certificate bytes when comparing.

Related Tools

Last updated 2026-10-09