Certificate Decoder

Decode X.509 SSL/TLS certificates in PEM format. All processing is done in your browser for maximum security and privacy.

PEM Format Support Detailed Analysis 100% Client-Side

How to Use Certificate Decoder

1

Paste Certificate

Copy your PEM-encoded certificate including the BEGIN/END headers and paste it into the input field

2

Auto Decode

The tool automatically parses the ASN.1/DER structure and extracts all certificate fields

3

Inspect Details

View subject, issuer, validity dates, SANs, public key info, and SHA-256 fingerprint

What is X.509?

X.509 is an ITU-T standard for defining the format of public key certificates. An X.509 certificate binds an identity (subject) to a public key and is signed by a Certificate Authority (CA). SSL/TLS certificates used for HTTPS websites are the most common application of X.509 certificates.

SSL/TLS Certificates

X.509 certificates are the foundation of HTTPS, verifying server identity and enabling encrypted communication

Public Key Infrastructure

X.509 defines the format for public key certificates used in PKI to bind identities to cryptographic keys

ASN.1/DER Encoding

Certificates use ASN.1 Distinguished Encoding Rules (DER) for their binary structure, wrapped in PEM Base64 for text transport

PEM vs DER vs CRT vs PFX — Certificate Formats

The same X.509 certificate can be stored in several file formats. Knowing which one you have saves time — here is how to tell them apart:

Format Extensions Encoding Typical Use
PEM .pem, .crt, .cer Base64 ASCII with BEGIN/END headers Web servers (Nginx, Apache), most Linux tools — the format this tool decodes
DER .der, .cer Raw binary ASN.1 Java keystores, some Windows and embedded tools
P7B / PKCS#7 .p7b, .p7c Base64 ASCII, certificates only (no private key) Windows certificate chain import, IIS
PFX / PKCS#12 .pfx, .p12 Binary, password-protected, may include private key Windows import/export, IIS, code signing bundles

Quick test: if the file opens in a text editor and shows -----BEGIN CERTIFICATE-----, it is PEM. If it looks like binary garbage, it is DER or PFX.

Useful OpenSSL Commands

Prefer the command line? These OpenSSL commands do what this tool does — decode, check dates, and fingerprint a certificate:

openssl x509 -in cert.pem -text -noout

Decode and display all certificate fields

openssl x509 -in cert.pem -noout -dates

Show only the validity dates (notBefore / notAfter)

openssl x509 -in cert.pem -noout -fingerprint -sha256

Print the SHA-256 fingerprint

openssl x509 -in cert.der -inform DER -text -noout

Decode a binary DER certificate

openssl x509 -in cert.pem -noout -subject -issuer

Show subject and issuer only

openssl s_client -connect example.com:443 -showcerts

Fetch the certificate chain from a live server

Certificate Fields Reference

What each decoded field means and why it matters:

Subject

The identity the certificate was issued to. Common components: CN (common name), O (organization), C (country).

Issuer

The Certificate Authority that signed this certificate. If subject equals issuer, the certificate is self-signed.

Serial Number

A unique number assigned by the issuing CA. It is used to check revocation status (CRL / OCSP).

Validity (Not Before / Not After)

The time window in which the certificate is valid. Outside this window, browsers and clients reject it.

Public Key & Key Size

The public key bound to the identity. 2048-bit RSA or 256-bit EC are the current norms; 1024-bit RSA is deprecated.

Subject Alternative Names (SANs)

The list of hostnames and IPs the certificate covers. Since 2015 browsers match against SANs, not the CN — a cert for example.com must list www.example.com explicitly or it will not validate.

Signature Algorithm

How the CA signed the certificate. SHA-256 and up are required; SHA-1 signatures are rejected by modern browsers.

Fingerprint (SHA-256)

A hash of the whole DER-encoded certificate. Used for pinning and comparing certificates across systems.

Frequently Asked Questions

What certificate formats are supported?

The tool supports PEM-encoded certificates (-----BEGIN CERTIFICATE-----). DER and P7B formats are not currently supported.

Does it verify the certificate chain?

The tool decodes and displays certificate details but does not verify the chain of trust against root CAs.

Can I decode certificate signing requests (CSR)?

Currently only X.509 certificates are supported. CSR decoding may be added in a future update.

What is the difference between PEM, DER, CRT, and PFX?

PEM is Base64-encoded text with BEGIN/END headers (extensions .pem, .crt, .cer). DER is the raw binary ASN.1 form of the same data. CRT and CER are just extension names that can hold either PEM or DER. PFX/PKCS#12 is a password-protected binary bundle that can include the private key, used mainly on Windows.

Why does my browser say the certificate is invalid even though it decodes fine?

Decoding and validating are different things. A certificate can parse perfectly but still fail validation because it is expired, the hostname is not in the SANs list, the chain does not lead to a trusted root CA, or it was revoked. This tool shows you the decoded fields — check the validity dates and SANs first.

Is it safe to paste my SSL certificate into this tool?

Yes. An SSL certificate is public information — every visitor of your site receives it. It contains no secret data. Never paste your private key anywhere, though: this tool does not need it and cannot use it.

What belongs in a certificate chain and how long should it be?

A served chain contains the leaf certificate plus the intermediate CAs that connect it to a trusted root - typically 2-3 certificates total. The root itself should not be sent: clients already hold roots in their trust store. A missing intermediate is the single most common cause of works-in-my-browser-but-fails-on-mobile TLS errors, since some clients cache or guess intermediates while others don't.

How do I check expiration dates and SANs before they cause an outage?

Decode the certificate and read the validity block: notBefore is the issue date, notAfter the expiry - plan renewal at least 30 days before notAfter. The SANs (Subject Alternative Names) list every hostname the certificate covers; a name missing from that list produces a certificate-name error in browsers even when the CN matches. This tool shows both fields decoded in place.

{-- * External Resources Component(#18 Phase 3b 内容佐证工程) * 工具页「权威引用」区块:RFC / W3C / WHATWG / ECMA / IANA / 官方规范站 / Wikipedia。 * * - 接受 :slug 属性 → 经 config/tool-sources.php 家族矩阵渲染该工具的权威引用 * - slug 未命中映射时不渲染(无权威来源的工具静默跳过) * - 链接 title 保持英文(引用源专名);description 经 * common.resources.descriptions.{key} 本地化,lang 未命中回退英文(线上不裸奔) * - 链接保持 dofollow(rel="noopener noreferrer") * * @param string|null $slug --}}