SSL certificate decoder
Paste several PEM certificates at once (a full chain) to decode each certificate’s validity, days remaining and expiry state, check the issuer/subject chain order, and match your hostname against the SAN DNS / IP entries (wildcards such as *.example.com included). Local parsing only — no TLS connection is ever opened.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Chain and hostname
Decoding uses a self-written ASN.1 / X.509 parser locally (reusing the pem-decoder and certificate-decoder implementations) and only reads the text you paste.
Result
Paste a PEM chain (and optionally a hostname), then press Decode chain.
What this tool does
- Paste the fullchain.pem exported from a server in one go and check every certificate’s validity and days remaining — the classic incident is renewing the leaf while forgetting the intermediate.
- Debug a hostname mismatch: enter the failing hostname and see whether the hit is an exact SAN entry, a wildcard, or only the deprecated CN — and whether `*.example.com` was accidentally written as `*.sub.example.com`.
- Confirm the chain order: end-entity → intermediate → root. When the order is wrong or an intermediate is missing, the issuer/subject link check points at the exact certificate.
- Pre-renewal health check: paste the new chain and make sure the hostnames and CA flags (basicConstraints CA:TRUE/FALSE) are what you expect.
Example
Input
Three certificates pasted in order (an openssl-generated test chain): leaf (CN=www.example.com, SAN with example.com, *.example.com, 127.0.0.1, admin@example.com) + inter (UniKit Test Intermediate CA, pathlen:0) + root (UniKit Test Root CA, self-signed); hostname www.example.com
Output
3 certificates; order check passed (every issuer matches the next subject and the chain ends with a self-signed root); validity check passed; hostname matched via *.example.com (wildcard SAN match); leaf validity 2026-10-10T08:28:53.000Z → 2027-11-11T08:28:53.000Z, root valid until 2036-10-07T08:28:53.000Z
Change the hostname to a.b.example.com and it reports no match — a wildcard covers exactly one label. Use 127.0.0.1 and it hits the IP entry in the SAN.
Frequently asked questions
Does this tool connect to my server and fetch the certificate?
No. It only parses the PEM text you paste — no TLS handshake, no intermediate download — so it needs no network and cannot be influenced by a man in the middle. To grab a live certificate use `openssl s_client -connect host:443 -showcerts`.
In which order should the chain be?
End-entity certificate first, then the intermediate CA that issued it, then the self-signed root — exactly the order of fullchain.pem. A wrong order still decodes, but the tool reports that some certificate’s issuer does not match the next subject; leaf + root alone is also flagged, because the intermediate is missing.
Which hostnames does `*.example.com` actually cover?
Per RFC 9525 a wildcard replaces exactly one left-most label: `*.example.com` covers `www.example.com` and `api.example.com`, but not `example.com` (too few labels) and not `a.b.example.com` (too many). The tool follows that rule and tells you whether the hit was an exact entry or a wildcard one.
Why does it say “CN only”?
Because the certificate has no DNS entries in its SAN, so the tool falls back to the CN using the old RFC 6125 rule. Modern browsers (Chrome, Safari, Edge) only look at the SAN and reject CN-only certificates outright, so that warning means you should reissue with a proper SAN.
Does “order looks right” mean the chain is trusted?
No. This check is textual: whether one certificate’s issuer equals the next one’s subject, and whether the chain ends with a self-signed certificate. Real trust needs signature verification with the issuer’s public key, validity and revocation checks (CRL / OCSP) and a root that exists in your local trust store — all of which need extra data or network access this tool deliberately avoids.
Keywords:ssl certificatecertificate chainpem chainsan matchwildcard certificateexpiry checkSSL 证书证书链有效期剩余天数域名匹配通配符证书