X509

X.509 Certificate Decoder

Inspect PEM or DER certificate identity, SANs, validity, usage, and fingerprint

Security & Auth
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026
PEM / DER X.509

Parsing shows certificate claims; it does not validate the full trust chain or revocation status.

Certificate summary

Subject, issuer, SANs, usages, validity, and fingerprint will appear here.

About this tool

X.509 Certificate Decoder parses pasted PEM certificates and uploaded PEM, CRT, CER, or binary DER files. It reports Subject and Issuer distinguished names, serial number, validity dates, public-key and signature algorithms, Subject Alternative Names, Key Usage and Extended Key Usage values, self-signature status, and a SHA-256 fingerprint. Current-time status only compares the local clock with notBefore and notAfter. Parsing one certificate does not validate its issuer chain, hostname, revocation status, certificate transparency records, or server TLS configuration. The input must contain exactly one CERTIFICATE PEM block or one binary DER SEQUENCE, with no additional blocks or trailing bytes. The file size limit is 2 MB. These checks enforce outer container boundaries; the parser is not a complete DER canonicality or certificate-policy validator.

Scenario Recipes

01

Check a certificate before an SSO rollover

Goal: Verify the exact signing certificate identity and validity window

  1. Open the certificate received from the identity provider.
  2. Record its SHA-256 fingerprint, validity dates, Subject, Issuer, and key usage.
  3. Compare the fingerprint through a separate trusted channel before updating the service provider.

Result: A reviewable certificate record without exposing private keys or contacting the endpoint.

Production Snippets

Compare the exact certificate with OpenSSL

sh

openssl x509 -in certificate.pem -noout -subject -issuer -dates -fingerprint -sha256
Expected: the same SHA-256 fingerprint and validity timestamps.
Appending bytes to a DER certificate is an input error here, even if a permissive parser can read the first object.

Frequently Asked Questions

Which certificate formats are supported?

Paste exactly one CERTIFICATE PEM block or open one PEM/CRT/CER/binary DER certificate file up to 2 MB. Bundles, unrelated PEM labels, text prefixes and DER trailing bytes are rejected.

Does the decoder validate the certificate chain?

No. It parses one certificate and can test its self-signature, but it does not build a chain to a trusted root.

What does Within validity dates mean?

Only that the current device time falls within the inclusive notBefore–notAfter interval. A future or expired certificate is marked separately; even an in-date certificate may be untrusted or revoked.

Can it check whether a certificate matches a hostname?

It lists Subject Alternative Names for inspection but does not apply wildcard, IDNA, name-constraint, or application-specific hostname rules.

What is the SHA-256 fingerprint used for?

A fingerprint identifies the exact DER certificate bytes and is useful for an out-of-band comparison or inventory record.

Is the certificate sent to a TLS server?

No. File parsing, extension extraction, self-signature checking, and fingerprint calculation all run locally.

Keep browsing