Certificate, CSR or key
Paste an X.509 certificate, a certificate signing request (CSR), a key or a full PEM chain, or load a .crt, .cer, .der, .p7b, .pfx or .p12 file. You will see the subject, SANs, validity, extensions and fingerprints, whether the chain is in order and properly signed, and whether the private key matches the certificate. Nothing leaves your browser.
You can paste several blocks together (certificate, intermediates and key) or drop a file here

How it works

An X.509 certificate is a signed document that binds a public key to a name: a domain, a person or an organization. What travels between servers and files is its binary form (DER), and what you copy and paste is that same structure in Base64 between the BEGIN CERTIFICATE and END CERTIFICATE lines, the PEM format. Inside there is a subject, an issuer, a validity period, the public key and extensions that state what it can be used for and where to check whether it has been revoked.

The tool recognizes certificates, PKCS#10 certificate signing requests (CSR), PKCS#8, PKCS#1 and SEC1 private keys, public keys, PKCS#7 bundles (.p7b) and PKCS#12 files (.pfx, .p12). If you paste several blocks together, it sorts the chain from the end-entity certificate up to the root, verifies each signature with the issuer's key and compares the private key with every certificate and CSR to tell you which one matches which.

It also converts between formats, builds the .pfx that IIS and Azure require from the certificate and the key, and generates a new CSR with its private key or a self-signed certificate for testing. Everything is done with your browser's cryptography API: neither the certificates nor the keys are sent to a server.

Examples

ISRG Root X1 · SHA-25696:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6The SHA-256 fingerprint of the Let's Encrypt root. It is the one published by the authority and by trust stores: if the fingerprint of your file matches, it is exactly that certificate.
ISRG Root X1 · pin SPKIC5+lpZ7tcVwmwQIMcRtPbsQtWLABXhQzejna0wHFr8M=The SHA-256 of the public key in Base64. It is the value that goes into pin-sha256 in Android's network security configuration or into an app's certificate pinning, and it does not change when the certificate is renewed if the key is reused.
root.crt + intermediate.crt + server.crtserver.crt + intermediate.crt + root.crtnginx and HAProxy take the first certificate in the file as the server certificate. If the chain is reversed, nginx fails with key values mismatch because it compares the private key with the root certificate.
openssl pkcs12 -in viejo.pfx -legacy -nodes | openssl pkcs12 -export -out nuevo.pfxPBES2 · AES-256-CBC · MAC SHA-256.pfx files exported by older Windows versions or OpenSSL 1.x are encrypted with RC2 and 3DES, which browsers do not implement. This command re-encrypts them with AES, the format OpenSSL 3 uses by default.

Use cases

  • Check, before installing it, that the certificate sent by the authority covers every domain (SAN) and that the expiration date is the expected one.
  • Find out which of the private keys left on the server matches each certificate, without having to compare moduli with OpenSSL.
  • Find out why a client does not trust your site: a missing intermediate, an out-of-order chain or a certificate signed with SHA-1.
  • Generate the CSR to buy or renew a certificate, with the key created on your machine and the equivalent OpenSSL command in case you prefer to do it on the server.
  • Convert a .crt and its .key into a .pfx for IIS, Azure App Service or a Java keystore, or extract the certificate and the key from a .pfx for nginx.
  • Get a certificate's fingerprint or SPKI pin to set up certificate pinning in a mobile app or to validate a client certificate.

Frequently asked questions

Is it safe to paste my private key here?

The key is processed with the Web Crypto API inside your browser and is not sent to any server; you can confirm this in the Network tab of the developer tools. Still, good practice is to treat any production key as a secret: paste it only into tools you trust and close the tab when you are done.

What is the difference between PEM, DER, CRT, CER, P7B and PFX?

DER is the certificate in binary form and PEM is that same binary in Base64 between BEGIN and END lines. The .crt and .cer extensions do not indicate the format: they can contain either one. A .p7b is a PKCS#7 bundle with several certificates and no key. A .pfx or .p12 is a PKCS#12: it stores the certificate, the intermediates and the private key together, encrypted with a password.

How do I know if my server is missing the intermediate?

Paste what you have configured on the server. If the chain ends in a certificate that is not self-signed, a link is missing: its Authority Information Access extension usually includes, under CA Issuers, the address to download the issuer from. Desktop browsers sometimes fetch it on their own, but Android, curl and most libraries do not, so the error only shows up on some clients.

How long can a public TLS certificate last?

Since September 2020, browsers reject certificates valid for more than 398 days. In 2025 the CA/Browser Forum approved lowering the maximum in stages: 200 days for certificates issued from March 15, 2026, 100 days from March 2027 and 47 days from March 2029. That is why it is worth automating renewal with ACME. A company's internal CAs are not subject to that limit.

RSA or ECDSA for the CSR?

ECDSA P-256 offers security comparable to 3072-bit RSA with much smaller keys and signatures, and the server completes the handshake faster. All current browsers and systems support it. RSA 2048 is still the safe choice if you have very old clients, embedded devices or a system that only accepts RSA.

Is it enough to put the domain in the common name (CN)?

No. Since Chrome 58, in 2017, browsers only look at the subject alternative names (SAN) and ignore the CN. Every domain the certificate will be used for, including the one in the CN, must be in the SAN list. A wildcard such as *.example.com covers a single level: it works for www.example.com but not for example.com or a.b.example.com.