Certificate & CSR Decoder
Read certificates, CSRs, .p7b bundles and CRLs — then check the chain reaches a trusted root, covers your host name, follows the CA/Browser Forum rules, and isn’t revoked.
How to use
- Paste PEM blocks or open a file — or use “Get the chain from a server” for a ready command.
- Read the trust verdict, the expiry overview (for several certificates), then the lint and details.
- Type a host name to check coverage; add the CA’s CRL to check revocation.
Get the chain from a server
This page cannot connect to servers. Run this command, then paste its output in the box above.
Common questions
Is it safe to paste a certificate here?
Yes. Certificates and CSRs are public by design, and this page cannot send anything anywhere: your browser blocks every connection it tries to make. Never paste a private key — the decoder refuses them.
How do I check a website’s certificate chain?
Open “Get the chain from a server”, enter the host name and run the command it gives you. Paste the output here to see whether the chain reaches a trusted root, covers the host name and is in the right order.
Why does my certificate show “not trusted”?
Usually an intermediate certificate is missing from what the server sends, or the certificate comes from a private CA. The chain check shows exactly which link is missing.
Known limitations
- No network: revocation is checked only against a CRL you paste (no OCSP), and Certificate Transparency logs are not queried.
- Trust uses a bundled snapshot of Mozilla’s root store; Microsoft, Apple and Google stores differ slightly, and your organisation may add private roots.
- The lint covers the most common Baseline Requirements rules, not all of them. Name constraints and policy mapping are not evaluated.
- Private keys are refused on purpose.
- Files over 50 MB are not opened — certificates, bundles and CRLs are far smaller, so it is almost certainly the wrong file.
- Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works
Related reading on CipherMind
Standards & references
- RFC 5280 — X.509 certificates and CRLs (opens in a new tab)
- RFC 9525 — host-name matching (replaces RFC 6125) (opens in a new tab)
- CA/Browser Forum TLS Baseline Requirements (opens in a new tab)
- CCADB — source of the Mozilla root list (opens in a new tab)
- RFC 2986 — PKCS #10 CSRs (opens in a new tab)
- RFC 5652 — CMS / PKCS #7 (.p7b) (opens in a new tab)