Certificate Fingerprint Calculator
Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.
Paste a PEM certificate on the left.
How it works
A certificate fingerprint is a digest over the full DER-encoded certificate — the same value
openssl x509 -fingerprint reports, and the same value a browser's own certificate viewer shows. It
identifies one exact certificate file, useful for confirming two copies are identical or matching against a
known-good value someone published out of band.
Not an SPKI pin
This is a whole-certificate digest, not a public-key pin. HPKP-style pinning hashes only the SubjectPublicKeyInfo, a different value that survives certificate renewal on the same key — a fingerprint here changes every time the certificate is reissued, even for the identical key pair.
Example
Two certificates issued for the same domain a year apart, on the same key, will show completely different fingerprints — the fingerprint identifies the certificate file, not the underlying key or the domain it names.
Frequently asked questions
Why compute SHA-1 at all when it is broken for collision resistance?
Certificate fingerprinting is an identity check, not a signature scheme — you are comparing a known-good value against what you have, not defending against a chosen-prefix attack. SHA-1 fingerprints are still what a lot of existing tooling (older cert-pinning configs, some CLI output) prints by default, so it stays useful for matching against that.
Does this match what my browser shows in its certificate viewer?
Yes — this is the same DER-bytes digest every certificate viewer computes, so the SHA-256 fingerprint shown here matches a browser's own certificate details panel exactly for the same certificate file.
Why not add MD5? Some old tools still print it.
The browser's WebCrypto API, which this tool relies on for every digest across this site, does not implement MD5, and this site does not hand-roll cryptographic primitives to fill that one gap — the same reasoning behind every other hashing tool here excluding it.
Related tools
X.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalCSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalSSH Public Key Inspector
Paste an OpenSSH public key line to read its type, size and SHA256 fingerprint.
LocalSecret Pattern Detector
Scan pasted text or code for the shape of a leaked API key, token or private key.
LocalPassword Entropy Checker
A charset-and-length entropy estimate, with the math and its limits shown, not a bare score.
Local