Skip to main content
QUIETLYTIC
Cybersecurity

X.509 Certificate Decoder

Paste a PEM certificate to read its subject, issuer, validity, key and extensions.

Local · nothing leaves this browser Waiting for a certificate
Esc Clear
Decoded certificate

Paste a PEM certificate on the left.

How it works

An X.509 certificate is DER-encoded ASN.1 wrapped in Base64 — this reads that byte structure directly: version, serial number, issuer and subject distinguished names, validity window, public key algorithm and size, and every extension present, including Subject Alternative Names, basic constraints and key usage.

What this does not do

It does not verify the signature, build a trust chain to a root CA, check revocation, or compare the validity window against today's date — all of those need a live connection or a trust store this browser-local tool deliberately does not have. It reads what the certificate says about itself, nothing more.

Not a live SSL/TLS checker

This never connects to a host. Paste a certificate you already have — a file on disk, one exported from a browser, one returned by openssl s_client — it never fetches one from a domain name.

Example

A certificate with SANs DNS:example.com, DNS:www.example.com but no DNS:api.example.com entry will fail hostname validation for api.example.com in every current browser, even if the Subject CN happens to read *.example.com — modern validation checks the SAN list, not the CN.

Frequently asked questions

Does this check if the certificate is currently valid or trusted?

No. It reports the notBefore/notAfter dates exactly as encoded and leaves the comparison to today's date to you — it does not verify the signature or walk a chain to a trusted root. Use openssl verify or a browser's own connection for an actual trust decision.

Why does it show the public key size but not the key itself?

The modulus/curve point length is the useful signal — 1024-bit RSA is weak, 2048+ is current baseline, P-256/Ed25519 are fine at their nominal size. The raw key material is shown too, since it is already public in the certificate, but the size is what actually answers "is this strong enough".

What is a Subject Alternative Name and why does it matter more than the Subject CN?

Modern browsers ignore the Subject Common Name for hostname matching entirely and check only the SAN list. A certificate with the right CN but no matching SAN entry fails validation in every current browser, which is why this tool lists SANs prominently rather than as a footnote.

Related tools

From the intelligence desk