Skip to main content
ToolsHub

SSL Certificate Decoder

Paste a PEM certificate to instantly decode all its fields: subject, issuer, SANs, and expiry dates.

Updated

Certificate is parsed on our servers. Never paste private keys here.

No certificate decoded yet

Paste a PEM certificate and click Decode Certificate to view its details.

How to use SSL Certificate Decoder

The SSL Certificate Decoder takes a PEM-encoded certificate and parses its contents into human-readable fields: subject, issuer, validity dates, serial number, signature algorithm, public key details and the Subject Alternative Names it covers. Certificates are stored as dense Base64 blocks that reveal nothing at a glance, so decoding one is the only way to confirm it contains what you expect before installing it. Use this tool to verify a certificate a vendor sent you, to read the SANs on an existing certificate, or to confirm the signature algorithm meets your security policy.

  1. Paste the full PEM certificate, including the BEGIN and END lines.
  2. Click Decode to parse the certificate’s fields.
  3. Review the subject, issuer and validity dates.
  4. Check the Subject Alternative Names and signature algorithm.
  5. Confirm the details match what you ordered before installing.

Reading the key certificate fields

The subject identifies who the certificate is for, and the issuer identifies the certificate authority that signed it. The validity dates bound when it can be used, while the Subject Alternative Names list every hostname it secures — for modern certificates the SAN list, not the older common name, is what browsers check. The signature algorithm shows how the certificate was signed; SHA-256 is the current norm and anything using the deprecated SHA-1 should be replaced. Decoding surfaces all of these so nothing is taken on trust.

Important certificate fields
FieldWhat it tells you
SubjectThe entity the certificate identifies
IssuerThe CA that signed it
Not Before / Not AfterThe validity window
SANAll hostnames covered
Signature algorithmHow it was signed (e.g. SHA-256)

PEM and DER encodings

Certificates come in two common encodings. PEM is the Base64 text form wrapped in BEGIN and END CERTIFICATE lines, easy to copy and paste and what this decoder expects. DER is the raw binary form, often carried in .cer or .der files. Converting between them changes only the container, not the certificate itself. If your certificate is in DER you can convert it to PEM with openssl before decoding. Knowing which form you have avoids the frustration of a paste that will not parse.

Glossary

PEM
A Base64 text encoding of a certificate wrapped in BEGIN/END lines.
DER
The binary encoding of a certificate, common in .cer files.
Subject
The identity a certificate is issued to.
SAN
Subject Alternative Name — the hostnames a certificate secures.
Signature algorithm
The cryptographic method used to sign the certificate, such as SHA-256 with RSA.

Related reading

Free · No spam

Get weekly tool tips & updates

New tools, power-user tips, and productivity hacks — delivered free every Friday.

No spam, ever. Unsubscribe with one click.

Related Network & DNS

Explore all Network & DNS.