Skip to main content
QUIETLYTIC
Cybersecurity

CSR Decoder

Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.

Local · nothing leaves this browser Waiting for a CSR
Esc Clear
Decoded request

Paste a PEM CSR on the left.

How it works

A PKCS#10 Certificate Signing Request carries a requested subject and public key, signed with the corresponding private key as proof of possession — no issuer, no validity dates, since those are the CA's to assign. This reads that structure: subject DN, public key algorithm and size, signature algorithm, and any requested Subject Alternative Names.

What was requested is not what will be issued

A CA is free to drop or override requested SANs, reject the requested subject entirely, or reissue under a different key policy. Nothing here predicts what the resulting certificate will actually contain — it decodes the request, not a promise.

Example

Requested SANs live inside an extensionRequest attribute (OID 1.2.840.113549.1.9.14), not the top-level subject field — a CSR with SANs entirely outside that attribute has none a CA will act on, no matter what the Subject CN reads.

Frequently asked questions

Where do the requested Subject Alternative Names come from in a CSR?

They live inside an extensionRequest attribute (a PKCS#9 attribute, OID 1.2.840.113549.1.9.14), not in the top-level subject field — a CSR with SANs entirely outside that attribute has none a CA will act on, no matter what the Subject CN says.

Can I use this to check if my CSR matches a specific private key?

No — that requires comparing the CSR's public key against the private key directly (e.g. openssl comparing modulus values), which needs the private key itself. This tool never asks for a private key and only ever sees the CSR you paste.

Why does the decoder reject a file that starts with '-----BEGIN CERTIFICATE-----'?

That PEM label is a certificate, not a request — this decoder specifically expects '-----BEGIN CERTIFICATE REQUEST-----' or '-----BEGIN NEW CERTIFICATE REQUEST-----'. Use the X.509 Certificate Decoder for an already-issued certificate instead.

Related tools

From the intelligence desk