Certificate Decoder
Decode X.509 SSL/TLS certificates in PEM format. All processing is done in your browser for maximum security and privacy.
How to Use Certificate Decoder
Paste Certificate
Copy your PEM-encoded certificate including the BEGIN/END headers and paste it into the input field
Auto Decode
The tool automatically parses the ASN.1/DER structure and extracts all certificate fields
Inspect Details
View subject, issuer, validity dates, SANs, public key info, and SHA-256 fingerprint
What is X.509?
X.509 is an ITU-T standard for defining the format of public key certificates. An X.509 certificate binds an identity (subject) to a public key and is signed by a Certificate Authority (CA). SSL/TLS certificates used for HTTPS websites are the most common application of X.509 certificates.
SSL/TLS Certificates
X.509 certificates are the foundation of HTTPS, verifying server identity and enabling encrypted communication
Public Key Infrastructure
X.509 defines the format for public key certificates used in PKI to bind identities to cryptographic keys
ASN.1/DER Encoding
Certificates use ASN.1 Distinguished Encoding Rules (DER) for their binary structure, wrapped in PEM Base64 for text transport
PEM vs DER vs CRT vs PFX — Certificate Formats
The same X.509 certificate can be stored in several file formats. Knowing which one you have saves time — here is how to tell them apart:
| Format | Extensions | Encoding | Typical Use |
|---|---|---|---|
| PEM | .pem, .crt, .cer | Base64 ASCII with BEGIN/END headers | Web servers (Nginx, Apache), most Linux tools — the format this tool decodes |
| DER | .der, .cer | Raw binary ASN.1 | Java keystores, some Windows and embedded tools |
| P7B / PKCS#7 | .p7b, .p7c | Base64 ASCII, certificates only (no private key) | Windows certificate chain import, IIS |
| PFX / PKCS#12 | .pfx, .p12 | Binary, password-protected, may include private key | Windows import/export, IIS, code signing bundles |
Quick test: if the file opens in a text editor and shows -----BEGIN CERTIFICATE-----, it is PEM. If it looks like binary garbage, it is DER or PFX.
Useful OpenSSL Commands
Prefer the command line? These OpenSSL commands do what this tool does — decode, check dates, and fingerprint a certificate:
openssl x509 -in cert.pem -text -noout
Decode and display all certificate fields
openssl x509 -in cert.pem -noout -dates
Show only the validity dates (notBefore / notAfter)
openssl x509 -in cert.pem -noout -fingerprint -sha256
Print the SHA-256 fingerprint
openssl x509 -in cert.der -inform DER -text -noout
Decode a binary DER certificate
openssl x509 -in cert.pem -noout -subject -issuer
Show subject and issuer only
openssl s_client -connect example.com:443 -showcerts
Fetch the certificate chain from a live server
Certificate Fields Reference
What each decoded field means and why it matters:
Subject
The identity the certificate was issued to. Common components: CN (common name), O (organization), C (country).
Issuer
The Certificate Authority that signed this certificate. If subject equals issuer, the certificate is self-signed.
Serial Number
A unique number assigned by the issuing CA. It is used to check revocation status (CRL / OCSP).
Validity (Not Before / Not After)
The time window in which the certificate is valid. Outside this window, browsers and clients reject it.
Public Key & Key Size
The public key bound to the identity. 2048-bit RSA or 256-bit EC are the current norms; 1024-bit RSA is deprecated.
Subject Alternative Names (SANs)
The list of hostnames and IPs the certificate covers. Since 2015 browsers match against SANs, not the CN — a cert for example.com must list www.example.com explicitly or it will not validate.
Signature Algorithm
How the CA signed the certificate. SHA-256 and up are required; SHA-1 signatures are rejected by modern browsers.
Fingerprint (SHA-256)
A hash of the whole DER-encoded certificate. Used for pinning and comparing certificates across systems.
Frequently Asked Questions
The tool supports PEM-encoded certificates (-----BEGIN CERTIFICATE-----). DER and P7B formats are not currently supported.
The tool decodes and displays certificate details but does not verify the chain of trust against root CAs.
Currently only X.509 certificates are supported. CSR decoding may be added in a future update.
PEM is Base64-encoded text with BEGIN/END headers (extensions .pem, .crt, .cer). DER is the raw binary ASN.1 form of the same data. CRT and CER are just extension names that can hold either PEM or DER. PFX/PKCS#12 is a password-protected binary bundle that can include the private key, used mainly on Windows.
Decoding and validating are different things. A certificate can parse perfectly but still fail validation because it is expired, the hostname is not in the SANs list, the chain does not lead to a trusted root CA, or it was revoked. This tool shows you the decoded fields — check the validity dates and SANs first.
Yes. An SSL certificate is public information — every visitor of your site receives it. It contains no secret data. Never paste your private key anywhere, though: this tool does not need it and cannot use it.
A served chain contains the leaf certificate plus the intermediate CAs that connect it to a trusted root - typically 2-3 certificates total. The root itself should not be sent: clients already hold roots in their trust store. A missing intermediate is the single most common cause of works-in-my-browser-but-fails-on-mobile TLS errors, since some clients cache or guess intermediates while others don't.
Decode the certificate and read the validity block: notBefore is the issue date, notAfter the expiry - plan renewal at least 30 days before notAfter. The SANs (Subject Alternative Names) list every hostname the certificate covers; a name missing from that list produces a certificate-name error in browsers even when the CN matches. This tool shows both fields decoded in place.
Related Tools
JWT Parser
Decode and verify JSON Web Tokens (JWT) on the spot. View header, payload, and signature details with easy-to-read timestamps
SAML Decoder
Decode SAML assertions from Base64-encoded XML
Base64 URL Decoder Parser
Decode and encode Base64, parse URL-encoded strings, preview Base64 images, and decode JWT header or payload segments
Authoritative References
Primary sources behind this tool - official standards and specifications, not secondhand summaries.
RFC 5280 - Internet X.509 PKI Certificate and CRL Profile
The IETF profile of X.509 certificates: fields, extensions, SANs, and revocation.
X.509 - Wikipedia
The X.509 public key infrastructure certificate format and its fields.
MDN Web Docs - TLS Certificates
Mozilla reference on TLS certificates and how browsers validate the chain of trust.