Encrypt Online
Theme

X.509 Certificate Parser

Decode PEM certificates and inspect key details

Read certificate fields here. Check the certificate chain and revocation status separately before using it.
Inspect PEM certificatesDecode one certificate or a bounded PEM bundle into readable identity, validity, key, and extension fields
Other PEM block types are counted and skipped. They are never included in the decoded summary.
What the X.509 Certificate Parser Decodes

Decode a PEM certificate or certificate bundle into readable X.509 fields. The parser separates identity, validity, public-key fingerprints, names, usage restrictions, and critical-extension notes so you can find the field that matters without scanning a raw ASN.1 dump.

How to Read the Certificate Fields
  • Subject identifies the certificate holder; issuer names the signing authority recorded in the certificate.
  • SANs contain the DNS names, IP addresses, email addresses, or URIs represented by the certificate.
  • Key usage and extended key usage constrain what the certificate key is intended to do.
  • Basic constraints indicates whether the certificate is marked as a CA and may include a path-length limit.
  • The certificate fingerprint hashes the full certificate; the public-key fingerprint hashes only its SubjectPublicKeyInfo.
Checking the Certificate in Use

This parser reads the certificates you supply. Use the chain checker to check the links between them, then test the deployment with the client that will connect to it. That client needs the right trusted root, issuer certificates, hostname and revocation checks.

Inspect the Same Certificate with OpenSSL
# Decode one PEM certificate without printing its encoded body
openssl x509 -in certificate.pem -noout -text -fingerprint -sha256
X.509 Parser FAQ
Can I paste a certificate chain?

Yes. Paste complete CERTIFICATE blocks together and the page will decode each block in input order.

Does "inside the validity window" mean the certificate is trusted?

No. It means only that the inspection time falls inside the encoded validity window.

Why are there two SHA-256 fingerprints?

The certificate fingerprint identifies the full encoded certificate. The public-key fingerprint identifies its normalized public-key structure and can match across a certificate and CSR.

What does this parser verify?

It reads certificate fields and calculates fingerprints. Use the chain checker for certificate links, then check revocation and hostname requirements in the client that will use the certificate.