CSR Decoder
Decode PKCS#10 CSR subject, SANs, public key, signature, and fingerprints
A valid CSR signature does not prove domain control, requester identity, or CA issuance.
Subject, SANs, public key, signature algorithm, and fingerprints will appear here.
About this tool
CSR Decoder parses PEM or binary DER PKCS#10 certificate signing requests and extracts the requested Subject, Common Name, Subject Alternative Names, public-key algorithm and size or curve, signature algorithm, extension count, and attribute OIDs. It verifies the CSR's self-signature and calculates SHA-256 fingerprints for both the complete request and SubjectPublicKeyInfo. Signature validity only proves that the request was signed by the included private key; it does not validate domain control, requester identity, policy compliance, or whether a certificate authority will issue the certificate. Input is one CERTIFICATE REQUEST or NEW CERTIFICATE REQUEST PEM block, or one binary DER SEQUENCE, up to 2 MB. Extra blocks and trailing bytes are rejected. A parsed request with a failing self-signature remains visible with an invalid-signature label; parsing alone does not make it ready for submission.
Scenario Recipes
Review a CSR before certificate submission
Goal: Catch identity or key mistakes before sending a request to a CA
- Open the CSR and confirm its self-signature is valid.
- Review Subject, SANs, key parameters, and signature algorithm against the certificate profile.
- Record the public-key fingerprint and submit the original CSR through the approved CA workflow.
Result: A locally reviewed request with key identity and requested names documented.
Production Snippets
Verify a request independently before submission
sh
openssl req -in request.csr -noout -verify -subject -text
Expected: self-signature verify OK for an unchanged valid CSR.
Changing the final signature byte must display Signature invalid (or reject an invalid container), never Signature valid.Frequently Asked Questions
Which CSR formats are supported?
Use one CERTIFICATE REQUEST or NEW CERTIFICATE REQUEST PEM block, or open a binary DER .csr file up to 2 MB. Multiple blocks and trailing DER bytes are rejected.
Does it show Subject Alternative Names?
Yes. SAN values requested through the extensionRequest attribute are listed by type.
What does Signature valid prove?
It proves the request data matches the signature made by the included public key's corresponding private key.
Does a valid signature prove domain ownership?
No. Domain control, organization identity, policy checks, and authorization are separate CA validation steps.
Why are there two SHA-256 fingerprints?
One identifies the complete CSR bytes; the other identifies its public-key SubjectPublicKeyInfo.
Is the CSR uploaded?
No. ASN.1 parsing, extension extraction, signature verification, and hashing run locally.
Why can details appear with Signature invalid?
PKCS#10 fields may be readable even when their self-signature fails. Preserve the original CSR for diagnosis and regenerate or correct it through the key owner before CA submission; do not edit signed fields by hand.
Keep browsing