Certificate and CSR decoder

Decode certificates, chains and CSRs in your browser: names, validity, key, chain order

Paste a certificate, a whole chain or a certificate signing request and read it in plain words: who it was issued to, which names it covers, when it expires, what key it uses and whether the chain is in the right order. PEM, DER and Base64 without the header lines all work, and so does a dropped .cer, .crt, .csr or .p7b file. Everything is decoded in your browser; nothing is uploaded.

Paste a certificate or CSR: subject, SAN, validity, key and chain order, decoded in your browser.

Runs in your browser

Or drop a .pem, .crt, .cer, .der, .csr, .req, .p7b or .p7c file here. Files are read in your browser and never uploaded. Private keys and .pfx files are refused.

How to use

  1. Paste one or more -----BEGIN CERTIFICATE----- blocks, or a -----BEGIN CERTIFICATE REQUEST----- block. You can also use Open a file or drop a file on the tool.
  2. Read the summary card first: names, validity with the days left, key and purpose. For a chain there is one card per certificate, leaf first.
  3. Check the warning lines under it. Each one names a single problem: expired, no SAN, a weak signature, a chain in the wrong order.
  4. Use Check it yourself to get the OpenSSL, certutil and PowerShell commands that show the same fields on your own machine.
  5. Use Share link to send a colleague the exact decode. The link carries the certificate in the part after #, which browsers never send to a server.

What the decoder checks

CheckWhat triggers itWhat it means for you
ValidityExpired, not yet valid, or fewer than 30 days left.Renew now; an expired certificate breaks every client at once.
Subject Alternative NameA server certificate with no SAN.Browsers ignore the Common Name. Without SAN entries the certificate matches no name at all.
SignatureSHA-1 or MD5.Clients reject it. Reissue with SHA-256.
KeyRSA shorter than 2048 bits.Too weak for public trust. Generate a new key and a new request.
LifetimeLonger than the CA/Browser Forum maximum for public TLS certificates.Information only: a public CA would not issue it. Certificates from your own internal CA are not bound by this rule.
Chain orderEach certificate should be issued by the next one.The decoder shows where the order breaks and the order that works. It compares names and key identifiers; it does not verify signatures.
Private keysAny private key or .pfx file.Refused before it is read, and never put into a share link.

FAQ

Frequently asked questions

Yes. A certificate and a signing request are public by design: the server sends its certificate to every client that connects. The decoder runs entirely in your browser and makes no network request with what you paste. What must never be pasted anywhere is the private key, and the tool refuses one if you try.

Practical examples

Example 1: what zaur.it actually serves. The leaf covers *.zaur.it and zaur.it, is issued by a Sectigo DV intermediate and is followed by that intermediate: two cards, chain order correct, days left shown. This is the certificate pair the Example button loads. Open this decode.

Example 2: a chain in the wrong order. The intermediate comes first and the leaf second, as it often ends up in a bundle file assembled by hand. The decoder says where the order breaks and which order works. Browsers are forgiving about chain order; many other TLS clients are not. Open this decode.

Example 3: check a CSR before it goes to the CA. A request with two DNS names in the SAN. Before you submit a request, confirm that every name is in the SAN list, the key is 2048 bits or more and the request is signed with SHA-256; a mistake here costs a reissue. Open this decode. Compare it with a request that has no SAN at all: open the CSR without SAN.

More test cases, including expired, SHA-1 signed and self-signed certificates, EC and Ed25519 keys and a PKCS #7 bundle, are in the Load a sample list and on the sample certificates page, where every file can be downloaded with its SHA-256 checksum.

Other tools


Related guides