X.509 Certificate Decoder
Inspect PEM or DER certificate identity, SANs, validity, usage, and fingerprint
Parsing shows certificate claims; it does not validate the full trust chain or revocation status.
Subject, issuer, SANs, usages, validity, and fingerprint will appear here.
About this tool
X.509 Certificate Decoder parses pasted PEM certificates and uploaded PEM, CRT, CER, or binary DER files. It reports Subject and Issuer distinguished names, serial number, validity dates, public-key and signature algorithms, Subject Alternative Names, Key Usage and Extended Key Usage values, self-signature status, and a SHA-256 fingerprint. Current-time status only compares the local clock with notBefore and notAfter. Parsing one certificate does not validate its issuer chain, hostname, revocation status, certificate transparency records, or server TLS configuration. The input must contain exactly one CERTIFICATE PEM block or one binary DER SEQUENCE, with no additional blocks or trailing bytes. The file size limit is 2 MB. These checks enforce outer container boundaries; the parser is not a complete DER canonicality or certificate-policy validator.
Scenario Recipes
Check a certificate before an SSO rollover
Goal: Verify the exact signing certificate identity and validity window
- Open the certificate received from the identity provider.
- Record its SHA-256 fingerprint, validity dates, Subject, Issuer, and key usage.
- Compare the fingerprint through a separate trusted channel before updating the service provider.
Result: A reviewable certificate record without exposing private keys or contacting the endpoint.
Production Snippets
Compare the exact certificate with OpenSSL
sh
openssl x509 -in certificate.pem -noout -subject -issuer -dates -fingerprint -sha256
Expected: the same SHA-256 fingerprint and validity timestamps.
Appending bytes to a DER certificate is an input error here, even if a permissive parser can read the first object.Frequently Asked Questions
Which certificate formats are supported?
Paste exactly one CERTIFICATE PEM block or open one PEM/CRT/CER/binary DER certificate file up to 2 MB. Bundles, unrelated PEM labels, text prefixes and DER trailing bytes are rejected.
Does the decoder validate the certificate chain?
No. It parses one certificate and can test its self-signature, but it does not build a chain to a trusted root.
What does Within validity dates mean?
Only that the current device time falls within the inclusive notBefore–notAfter interval. A future or expired certificate is marked separately; even an in-date certificate may be untrusted or revoked.
Can it check whether a certificate matches a hostname?
It lists Subject Alternative Names for inspection but does not apply wildcard, IDNA, name-constraint, or application-specific hostname rules.
What is the SHA-256 fingerprint used for?
A fingerprint identifies the exact DER certificate bytes and is useful for an out-of-band comparison or inventory record.
Is the certificate sent to a TLS server?
No. File parsing, extension extraction, self-signature checking, and fingerprint calculation all run locally.
Keep browsing