>_devtools

X.509 Certificate Decoder

Decode PEM certificates: subject, issuer, validity and expiry status, SAN, key usage, extensions, policies, AIA/CRL URLs, public key, and SHA-1/SHA-256 fingerprints.

What this does

Paste one or more PEM certificates (the text between -----BEGIN CERTIFICATE-----and -----END CERTIFICATE-----) or open a .pem, .crt, or.cer file. The decoder shows what openssl x509 -text -noout would, in a readable layout: subject and issuer, serial number, validity window with an expiry status, signature algorithm, public key details, and every extension.

What you get

  • Subject and issuer, split into their attributes (CN, O, OU, C, ...).
  • Not-before and not-after dates in UTC, with days remaining or days since expiry.
  • Subject alternative names: DNS names, IP addresses, emails, URIs.
  • Key usage, extended key usage, and basic constraints (CA flag and path length).
  • Subject and authority key identifiers, certificate policies, and any embedded CT timestamps.
  • CRL, OCSP, and CA-issuer URLs from the CRL distribution points and authority info access extensions, shown as text.
  • RSA modulus and exponent, or the EC curve and public point, plus the SPKI SHA-256 pin.
  • SHA-1 and SHA-256 fingerprints of the DER encoding, formatted like browsers and OpenSSL show them.

Behavior and limits

Validity is evaluated against your device's clock. Warnings call out SHA-1 or MD5 signatures, RSA keys under 2048 bits, and leaf certificates with no subject alternative name. Certificates are decoded, not validated: this page does not check trust, revocation, or hostnames, and it never contacts the URLs it lists. To check how certificates link together, use thecertificate chain viewer. Input is capped at 2 MB and 50 certificates.

Example

Click "Load example" for a sample leaf certificate with a SAN list, key usages, and AIA, CRL, and policy extensions. The same bytes decode identically with openssl x509 -in cert.pem -text.

Privacy

Parsing runs in your browser with the built-in WebCrypto API for hashing. The certificate is not uploaded or stored. Certificates are public data, but the page treats them like any other input.