>_devtools

CSR Decoder

Decode a PEM certificate signing request: subject, SAN, requested extensions, public key, signature algorithm, and whether the request's signature is valid.

What this does

A certificate signing request (CSR, PKCS#10) is what you send to a certificate authority to get a certificate. It holds your public key, the subject you are asking for, and optionally a list of requested extensions such as subject alternative names. This tool decodes a PEM CSR so you can check it before submitting, the same way openssl req -in request.csr -text -noout would.

What gets checked

  • Subject attributes: common name, organization, country, and the rest.
  • Requested SAN entries (DNS names, IP addresses, emails, URIs), key usage, extended key usage, and basic constraints.
  • Public key algorithm, size or curve, and its SPKI SHA-256 pin.
  • The self-signature. A CSR is signed with the private key that matches the public key it carries; the tool verifies that signature locally, which catches truncated or edited requests.
  • Weak signatures (SHA-1) and small RSA keys.

Typical mistakes it surfaces

A missing SAN is the most common one: browsers ignore the common name, and many CAs copy only the requested SAN list into the certificate. Another is generating the CSR from a different key than the one you deploy; compare the SPKI SHA-256 pin here with the one shown in thecertificate decoder to confirm they match.

Privacy

The request is parsed in your browser and never uploaded. A CSR contains no private key, but this page keeps the input in memory only.