Skip to main content
QUIETLYTIC
Cybersecurity

Certificate Fingerprint Calculator

Paste a PEM certificate, get its SHA-1 and SHA-256 fingerprint.

Local · nothing leaves this browser Waiting for a certificate
Esc Clear
Fingerprints

Paste a PEM certificate on the left.

How it works

A certificate fingerprint is a digest over the full DER-encoded certificate — the same value openssl x509 -fingerprint reports, and the same value a browser's own certificate viewer shows. It identifies one exact certificate file, useful for confirming two copies are identical or matching against a known-good value someone published out of band.

Not an SPKI pin

This is a whole-certificate digest, not a public-key pin. HPKP-style pinning hashes only the SubjectPublicKeyInfo, a different value that survives certificate renewal on the same key — a fingerprint here changes every time the certificate is reissued, even for the identical key pair.

Example

Two certificates issued for the same domain a year apart, on the same key, will show completely different fingerprints — the fingerprint identifies the certificate file, not the underlying key or the domain it names.

Frequently asked questions

Why compute SHA-1 at all when it is broken for collision resistance?

Certificate fingerprinting is an identity check, not a signature scheme — you are comparing a known-good value against what you have, not defending against a chosen-prefix attack. SHA-1 fingerprints are still what a lot of existing tooling (older cert-pinning configs, some CLI output) prints by default, so it stays useful for matching against that.

Does this match what my browser shows in its certificate viewer?

Yes — this is the same DER-bytes digest every certificate viewer computes, so the SHA-256 fingerprint shown here matches a browser's own certificate details panel exactly for the same certificate file.

Why not add MD5? Some old tools still print it.

The browser's WebCrypto API, which this tool relies on for every digest across this site, does not implement MD5, and this site does not hand-roll cryptographic primitives to fill that one gap — the same reasoning behind every other hashing tool here excluding it.

Related tools

From the intelligence desk