Utilo

Certificate Decoder

Decode X.509 SSL/TLS certificates, certificate chains and CSRs locally. Inspect subject, issuer, SANs, validity, key type, extensions, SHA-256/SHA-1 fingerprints and chain order without uploading anything.

What this certificate decoder does

openssl x509 -in cert.pem -text -noout works, but its output is long and easy to misread, and online decoders ask you to upload certificates to someone else's server. This tool decodes PEM-encoded X.509 certificates, whole certificate chains and certificate signing requests (CSRs) directly in your browser. It shows the subject and issuer, Subject Alternative Names, validity window with days remaining, key type and size, signature algorithm, key usage and other extensions, serial number and SHA-256 and SHA-1 fingerprints. For chains, it checks that each certificate was issued by the next one.

How to use it

  1. Paste one or more PEM blocks (-----BEGIN CERTIFICATE----- or -----BEGIN CERTIFICATE REQUEST-----), or upload a .pem, .crt or .csr file.
  2. Each certificate appears as a card with the key details at the top.
  3. For chains, follow the links between cards: a green link means the issuer matches the next certificate's subject.
  4. Copy fingerprints or SANs with one click.

Getting a certificate to decode

  • From a live server: openssl s_client -connect example.com:443 -showcerts </dev/null and copy the PEM blocks.
  • From a browser: click the padlock, view the certificate and export it as PEM (Base64).
  • From Kubernetes: kubectl get secret my-tls -o jsonpath='{.data.tls\.crt}' | base64 -d.

What to look for

  • SANs: modern browsers ignore the Common Name; the hostname must be in the SAN list.
  • Validity: public TLS certificates are limited to 398 days and are getting shorter. Watch the days-remaining badge.
  • Chain order: servers should send the leaf first, then intermediates. The root is optional.
  • Key size: RSA should be at least 2048 bits; ECDSA P-256 is a good default.
  • Fingerprints: compare SHA-256 fingerprints when pinning or verifying a certificate out of band.

Frequently asked questions

Is it safe to paste a certificate here?

Certificates and CSRs are public data, and decoding happens locally anyway. Never paste a private key into any website; this tool refuses PEM blocks that look like private keys.

Does it verify signatures against trusted roots?

It checks issuer/subject linkage within the chain you paste. It does not check revocation or your operating system's trust store.

Can it read DER or PKCS#12 files?

Paste PEM text. Convert DER with openssl x509 -inform der -in cert.der -out cert.pem.

What libraries are used?

Parsing uses @peculiar/x509 and fingerprints use the browser's Web Crypto API.

Yes. All processing happens directly in your browser using JavaScript, Web Workers and Web APIs. Nothing you type, paste or upload is sent to our servers.