CSR Parser & Signature Checker
Parse a PEM/DER CSR, show subject, public key and DNS/IP SANs, and verify its embedded signature locally.
Privacy: all processing happens locally in your browser. Your input never leaves your device.
What is CSR Parser & Signature Checker?
A CSR signature proves possession of its corresponding private key; it is not a certificate issued by a CA. This tool reads a PKCS#10 CSR's subject, public key, requested SANs and extensions, then verifies that its self-signature matches the public key. A valid result means the encoded request was not altered in a way that breaks its signature. It does not prove domain control, organizational identity or that a CA will issue a certificate.
How to Use
- Paste or import a PEM/DER CSR
- Review the subject, public key, DNS/IP SANs and requested extensions
- Check the signature result before sending the request into a CA workflow
FAQ
- Does a valid CSR signature prove I own the domain?
- No. It proves possession of the private key only; a CA still performs domain-control validation.
- Why are DNS and IP SANs separate?
- They are distinct name types. An IP address must be encoded as an IP SAN, not as DNS text, for client matching to work.
- Can I compare a CSR with my private key?
- Yes. Compare the CSR public key against the public key extracted from your private key; do not attach the private key to the CSR.
Related Tools
SSL Key Pair GeneratorGenerate RSA, ECC or SM2 PEM key pairs locally: RSA 2048/3072/4096 and P-256/P-384 are supported.Key Format ConverterConvert RSA PKCS#1 and general PKCS#8 private keys locally, optionally changing output password protection without changing the underlying key.Private Key Parameter ParserInspect public parameters of an RSA, ECC or SM2 private key and export its public key locally, without revealing private mathematical components.Public Key Parameter ParserParse the algorithm, RSA bit length or elliptic-curve parameters of an RSA, ECC or SM2 PEM/DER public key locally.CSR GeneratorCreate a local CSR and private key with DNS/IP SANs using RSA, ECC P-256/P-384 or SM2.Self-Signed SSL Certificate GeneratorGenerate local self-signed TLS certificates with DNS/IP SANs for development, intranets and controlled testing using RSA, ECC or SM2.
Last updated 2026-10-09