Paste a certificate (the block starting with —–BEGIN CERTIFICATE—–) to see exactly what it contains. Useful when a panel shows several certificates, when you receive a certificate by e-mail, or when you need the fingerprint for pinning or monitoring. For a live server use the SSL certificate checker instead.
Table of Contents
Command-line equivalent
openssl x509 -in cert.pem -noout -subject -issuer -dates -ext subjectAltName -fingerprint -sha256 shows the same fields. On Windows, certutil -dump cert.cer does the same for DER or PEM files.
If the certificate is in a .pfx/.p12 bundle, extract it first: openssl pkcs12 -in bundle.pfx -clcerts -nokeys -out cert.pem
Certificate decoder at a glance



Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, AlmaLinux wiki.
Related guides: Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions · CSF after ConfigServer: which fork should you run in 2026 (cPanel, DirectAdmin, Aetherinox, Sentinel)? · CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws.
Frequently asked questions
Why does it say CA certificate?
The certificate has basicConstraints CA:TRUE. That is normal for intermediate and root certificates, and for many self-signed test certificates, but a server certificate from a public CA should be an end-entity certificate.
Which fingerprint should I use?
SHA-256. SHA-1 fingerprints are shown only because some older tools and appliances still ask for them.
Can I decode a certificate chain?
Paste one certificate at a time; the tool reads the first PEM block it finds.