Skip to content

PEM certificate parser

Paste a PEM certificate taken from openssl, a browser or your server; the fields are parsed in your browser. The days left and expiry warnings, SAN names, key size, extensions, fingerprints and a chain-order check are shown. The certificate never leaves your browser.

Free tool · Infrastructure

You can paste a single certificate or a combined chain (leaf first, then intermediate and root certificates). Extra text between the blocks is ignored.

Parsed in your browser; the certificate is not sent. Do not paste a private key.

How do I get the certificate?
  • openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null
  • openssl x509 -in certificate.pem -noout -text
  • cat certificate.pem

www.ornek.example

Validity status

Calculating…

Dates are shown in UTC.

Subject
C=TR, O=Ornek Kurum, CN=www.ornek.example
Issuer
C=TR, O=Ornek Kurum, CN=Ornek Kok CA
Version
v3
Serial number
1A:7C:46:6F:E7:53:BC:A4:A2:71:33:6D:EB:79:7D:2F:68:BC:C9:DD
Signature algorithm
ecdsa-with-SHA256
Valid from
2026-10-06 14:30:10 UTC
Valid until
2036-10-03 14:30:10 UTC
Total period
3,650 days
Public key
EC prime256v1 (P-256), 256 bit
Alternative names (SAN)
DNS: www.ornek.example
DNS: ornek.example
IP: 192.0.2.10
Key Usage
digitalSignature
Extended Key Usage
serverAuth, clientAuth
Basic Constraints (CA)
No (end entity)
Subject Key Identifier
7D:BB:50:74:E6:23:AF:65:B9:BF:71:C1:EE:55:A6:2E:8E:76:DD:49
Authority Key Identifier
88:91:47:CC:56:E7:0E:E9:4B:27:4B:F0:8C:40:A9:C3:8E:5F:1E:90
Extensions
Basic Constraints; Key Usage (critical); Extended Key Usage; Subject Alternative Name; Subject Key Identifier; Authority Key Identifier

Name attributes

Name attributes
Subject
C = TR
O = Ornek Kurum
CN = www.ornek.example
Issuer
C = TR
O = Ornek Kurum
CN = Ornek Kok CA

What we read and how

  • PEM → base64 is decoded → ASN.1 DER (RFC 5280) is parsed. No outside library or server is used.
  • Days left = (end − now) ÷ 24 hours, rounded down. "Now" is taken from the browser clock after the page has loaded. Thresholds: 30, 14 and 7 days.
  • RSA key size = the bit length of the modulus; for EC the curve name (P-256, P-384…) and the curve's bit size are shown.
  • Fingerprint = the SHA-256 / SHA-1 digest of the whole DER data (WebCrypto); it has the same format as the output of openssl x509 -fingerprint.
  • Chain: each certificate's issuer name (raw DER bytes) is compared with the next one's subject name; AKI and SKI are checked as well.

This tool reads the fields of the certificate. It does not verify signatures, does not check whether the certificate has been revoked (CRL/OCSP) or whether it chains to a trust anchor, and it cannot see which certificate a server actually presents. Results are a preliminary assessment and no substitute for a security or compliance audit. Track expiry dates with your own monitoring as well.

Shall we review your certificate lifecycle, your automatic renewal and your monitoring together?

Request a meeting

01

How to use

  1. A

    Get the certificate as PEM: openssl s_client -connect yourdomain.com:443 -showcerts, cat certificate.pem from a file, or from your server's certificate folder. A browser's "Base-64 encoded" export also gives PEM.

  2. B

    Paste the text into the box. With several certificates they are parsed in order and the chain is checked. Do not paste a private key (BEGIN PRIVATE KEY); if you do, the tool warns and does not process it.

  3. C

    Look at the days left and the warnings first, then the SAN names, the key size and the extensions. Compare the fingerprint with a value you saw elsewhere to confirm you are looking at the right certificate.

02

What to look at in a certificate

The first place to look is the validity period: an expired certificate causes connection errors in clients, which is why the tool flags the days left with thresholds of 30, 14 and 7 days. Second is the SAN list: browsers and clients verify the server name against the SAN, not the subject CN, so the name you visit must be in the list (or covered by a wildcard).

Next look at the key type and size: at least 2048 bits for RSA and P-256 or above for EC are common. Key Usage and Extended Key Usage say what the certificate may be used for (for example serverAuth, clientAuth); Basic Constraints says whether it is a CA certificate. Weak signature algorithms (MD5, SHA-1) are flagged as warnings.

03

Chain order and why we do not verify the signature

A TLS server normally sends the leaf certificate and the intermediates; the root certificate sits in the client's trust store. In a chain the issuer of each certificate must be the subject of the next. If the order is broken or an intermediate is missing, some clients refuse the connection while others fetch the missing piece themselves and the mistake goes unnoticed. The tool checks this order and the name match.

Signature verification is a separate job: it needs the mathematical check of the signature with the issuer's key, a revocation lookup and a check of the trust anchor. This tool does none of these, and so it never says "the certificate is trusted" or "the chain is valid"; it only reports the fields it read and the name and key-identifier matches.

04

Fingerprints and privacy

The fingerprint is the digest of the certificate's whole DER data. It is used to compare a certificate with a value from another source or to pin it on a server. The tool shows SHA-256 and SHA-1; SHA-1 is only for comparison with older systems.

Certificates are public information but can contain domain and organisation names; even so, the text you paste does not leave your browser. A private key is a different matter: if it is captured, a fake server can be set up in the certificate's name. Never paste a private key into any online tool.

FAQ

Is the certificate I paste sent anywhere?
No. Parsing and the fingerprint calculation run as code in your browser; the text is not sent to any server or stored. The tool also makes no live lookups (OCSP, CRL, CT).
What happens if I paste my private key?
The tool recognises "PRIVATE KEY" blocks, shows a warning and does not decode the content. The text still sits in the box, so do not paste a private key into any tool. If you did, use the Clear button and, assuming the key may be compromised, consider replacing it.
Why does the tool not say "trusted certificate"?
Trust rests on verifying the signature with the issuer's key, the chain reaching a trust anchor, the revocation status and the name match. This tool only reads the fields in the certificate and checks name matching in the chain; it does not verify signatures. Only the client's trust store decides on trust.
Why are the days left a whole number?
The remaining time is rounded down to whole days: 6 days 20 hours is shown as "6 days". The thresholds (30, 14, 7) are flagged on that integer. The end date is given in UTC, so it may differ by a few hours from your local time.
Why does the SAN show only DNS and IP?
The most common types are DNS names and IP addresses; email and URI names are listed too. Other name types (such as otherName, directoryName) are only counted. A wildcard name (*.example.com) covers a single level of subdomains only.
Which formats can it read?
PEM-encoded X.509 certificates (BEGIN CERTIFICATE, TRUSTED CERTIFICATE, X509 CERTIFICATE) and a single base64 DER blob without headers. CSRs, public keys and PKCS#12 files are skipped because they are not certificates.

Do not let certificate expiry surprise you

Let us review your certificate inventory, automatic renewal, expiry monitoring and TLS configuration together. In a free discovery call we discuss where you stand and the risks.