Emergency server help: get in touch

SSL Certificate Decoder

Decode a PEM SSL/TLS certificate in your browser: subject, issuer, validity dates, SAN names, key, signature algorithm, serial number and SHA-256/SHA-1 fingerprints.

Status
Live
Last updated
October 3, 2026

Paste a certificate (the block starting with —–BEGIN CERTIFICATE—–) to see exactly what it contains. Useful when a panel shows several certificates, when you receive a certificate by e-mail, or when you need the fingerprint for pinning or monitoring. For a live server use the SSL certificate checker instead.

Command-line equivalent

openssl x509 -in cert.pem -noout -subject -issuer -dates -ext subjectAltName -fingerprint -sha256 shows the same fields. On Windows, certutil -dump cert.cer does the same for DER or PEM files.

If the certificate is in a .pfx/.p12 bundle, extract it first: openssl pkcs12 -in bundle.pfx -clcerts -nokeys -out cert.pem

Certificate decoder at a glance

SSL Certificate Decoder summary card: Paste a certificate (the block starting with -----BEGIN CERTIFICATE-----) to see exactly what it contains.
In short: Paste a certificate (the block starting with —–BEGIN CERTIFICATE—–) to see exactly what it contains.
Certificate decoder – overview of the steps
Certificate decoder: the sections of this tool at a glance.
SSL Certificate Decoder questions answered: Why does it say CA certificate? Which fingerprint should I use?
Answers: Why does it say CA certificate? Which fingerprint should I use?

Official documentation: Let’s Encrypt documentation, cPanel & WHM documentation, AlmaLinux wiki.

Related guides: Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions · CSF after ConfigServer: which fork should you run in 2026 (cPanel, DirectAdmin, Aetherinox, Sentinel)? · CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws.

Frequently asked questions

Why does it say CA certificate?

The certificate has basicConstraints CA:TRUE. That is normal for intermediate and root certificates, and for many self-signed test certificates, but a server certificate from a public CA should be an end-entity certificate.

Which fingerprint should I use?

SHA-256. SHA-1 fingerprints are shown only because some older tools and appliances still ask for them.

Can I decode a certificate chain?

Paste one certificate at a time; the tool reads the first PEM block it finds.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.