X.509 certificate decoder
Paste a PEM certificate to decode its X.509 fields: version, serial, signature algorithm, subject and issuer, validity with days remaining, key algorithm and size, extensions (SAN / keyUsage / basicConstraints / SKI / AKI / CRL / AIA), SHA-1 and SHA-256 fingerprints, and a self-signed verdict. Parsing is entirely local — no network requests.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Certificate
Decoding uses a self-written ASN.1 / X.509 parser (reusing the pem-decoder implementation) and runs locally; the SHA-1 / SHA-256 fingerprints are computed with the browser WebCrypto API. The certificate never leaves this page.
Result
Paste a PEM certificate and press Decode certificate.
What this tool does
- A production certificate is about to expire: paste the PEM and read the expiry, the days remaining and whether keyUsage / EKU still look right.
- Debug “certificate does not match the hostname”: see exactly which names the SAN carries (including wildcards and IPs) and whether there is only a CN with no SAN at all.
- Certificate inventory: record each certificate’s SHA-256 fingerprint (identical to openssl x509 -fingerprint -sha256) for change audits or to compare against a CDN configuration.
- Sanity-check a certificate you issued yourself: is it v3, what do basicConstraints and pathlen say, and are SKI / AKI present as a pair?
Example
Input
A test server certificate generated with openssl (CN=www.example.com, issued by an intermediate CA, SAN with example.com, *.example.com, 127.0.0.1 and admin@example.com)
Output
Version 3; serial 7b964dda6416bb6e5f79d116990b1cc177bd3dbd; signature algorithm sha256WithRSAEncryption; subject C=CN, O=UniKit, OU=Tools, CN=www.example.com; issuer …CN=UniKit Test Intermediate CA; validity 2026-10-10T08:28:53.000Z → 2027-11-11T08:28:53.000Z; public key RSA 2048 bits; SHA-256 fingerprint 58:66:CB:88:00:77:CD:64:E3:E4:79:A2:70:02:5D:40:C5:AC:81:4D:98:DD:7A:8F:08:CF:B5:8A:F2:43:80:D8; self-signed: no
The fingerprint matches `openssl x509 -in cert.pem -noout -fingerprint -sha256` byte for byte, including the upper case and the colon separators.
Frequently asked questions
Why is there no “is this chain trusted” verdict?
Trust requires verifying signatures (RSA / ECDSA), walking up through issuers to a root, and checking that root against a local trust store — that needs a trust store and downloads this tool deliberately does not do. It only decodes the certificate you paste. For chain order and per-certificate validity, use the SSL certificate decoder in this category.
How is “self-signed: yes” decided?
Subject and issuer are identical, and (when both exist) SKI equals AKI or one of them is missing. That is a structural check, not a cryptographic one; real self-signed verification would need to verify the certificate’s signature with its own public key.
Do hostname checks use SAN or CN?
Modern browsers only look at SAN (subjectAltName); CN was deprecated by RFC 6125 and browser policy years ago. A certificate with only a CN and no SAN is rejected outright by Chrome and Safari. This tool lists every DNS, IP, email and URI entry in the SAN so you can check the wildcard syntax.
What is the difference between keyUsage and extKeyUsage?
keyUsage limits what the public key may do cryptographically (digitalSignature, keyEncipherment, keyCertSign …), while extKeyUsage limits the scenarios the whole certificate is good for (serverAuth, clientAuth, codeSigning …). A server certificate usually has keyUsage = digitalSignature + keyEncipherment and an extKeyUsage containing serverAuth.
How are the fingerprints computed, and do they match openssl?
A fingerprint is a hash of the whole certificate DER. This tool computes SHA-1 and SHA-256 with the browser’s crypto.subtle.digest and prints them as upper-case hex separated by colons, exactly like `openssl x509 -fingerprint`. The DER length is shown too, which helps when comparing against a downloaded file.
Keywords:x509certificate decoderpemsanfingerprintsha256 fingerprint证书解析数字证书X.509有效期指纹自签证书