SSL & Security

SSL Certificate Decoder

X.509 Details

Decode a Certificate

Upload your SSL certificate file or paste the certificate text to decode its contents and view detailed information.

Tool features

Comprehensive SSL certificate decoding and analysis
4 checks

Certificate Parsing

Parse and decode X.509 certificates in PEM format

Public Key Info

Extract public key details including algorithm and key size

Detailed Analysis

View subject, issuer, validity, extensions, and more

Chain Support

Decode certificate chains with multiple certificates

What is certificate decoding & how it works

What is inside an X.509 certificate

An X.509 certificate binds a public key to an identity (a domain, organisation or person) and is signed by a certificate authority. In PEM form it is just Base64 between -----BEGIN CERTIFICATE----- markers, so you cannot read the details without decoding it.

Decoding unpacks the ASN.1 structure into readable fields: who it was issued to and by, the validity window, the Subject Alternative Names it covers, the key type and size, and extensions such as key usage. That is how you confirm a certificate is the one you expect before installing it or debugging a trust error.

Subject / Issuer
Who the certificate identifies, and the CA that signed it.
SAN
Subject Alternative Names: every hostname the certificate is valid for.
Validity
The notBefore / notAfter window outside which clients reject the certificate.

How to use this tool

Decode and inspect a certificate in four steps
1
Paste the certificate
Paste one or more PEM certificates, including the BEGIN/END CERTIFICATE lines, or upload the file.
2
Decode
Run the decoder to parse every certificate in the input.
3
Check the key fields
Review subject, issuer, SANs, validity dates, key algorithm and size, and extensions.
4
Confirm before deploying
Make sure the hostnames, expiry and issuer are what you ordered before installing the certificate.

Frequently asked questions

Common questions about decoding SSL certificates
5 Q&A

It turns a PEM certificate into readable fields: subject and issuer, serial number, validity dates, Subject Alternative Names, public key algorithm and size, signature algorithm, fingerprints and X.509 extensions.

Yes. Paste the leaf and intermediates together and each certificate is decoded separately, so you can check the issuer of one against the subject of the next.

Yes. A certificate is public: servers send it to every visitor. Never paste the private key, which is a different block starting with BEGIN PRIVATE KEY.

Run openssl x509 -in cert.pem -noout -text. For a DER file add -inform der.

Browsers ignore the Common Name and only match hostnames against the Subject Alternative Name list. Check that the exact hostname (or a matching wildcard) is in the SANs.