Certificate Viewer

All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.

About Certificate Viewer

The CSR.plus Certificate Viewer is a free X.509 certificate viewer that decodes any SSL/TLS certificate directly in your browser. Paste a PEM certificate or upload a .crt, .pem, or .cer file to read the subject, issuer, validity period, public key algorithm, SHA-1/SHA-256 fingerprints, SAN entries, and every X.509 extension — all computed locally with no upload.

System administrators and DevOps engineers use this online certificate viewer to verify that an issued certificate matches what was ordered, to inspect the certificate chain before deployment, and to audit certificate details without installing OpenSSL or other command-line tools. Because parsing runs entirely in your browser, sensitive certificate material never leaves your device.

Why use

  • View common name (CN), SAN, issuer, and validity dates at a glance
  • Check RSA or EC public key algorithm and key size against security baselines
  • Compare SHA-1 and SHA-256 fingerprints to confirm a certificate matches its key
  • Inspect every X.509 extension, including SAN and key usage, without OpenSSL

How to use

  1. Copy the full PEM block, starting with -----BEGIN CERTIFICATE----- and ending with -----END CERTIFICATE-----.
  2. Paste the block into the viewer, or click Upload to load a .crt, .pem, or .cer file (DER files are auto-detected).
  3. The viewer instantly parses the certificate and shows its fields in clearly labelled sections.
  4. Review the subject, issuer, validity, public key, fingerprints, SAN, and extensions to confirm everything is correct.

Frequently asked questions

▸Is my certificate uploaded to a server?

No. All decoding happens locally in your browser. The certificate text never leaves your device, keeping private material safe.

▸Which certificate formats are supported?

PEM text and uploaded .pem, .crt, and .cer files. DER-encoded certificates are detected and decoded automatically.

▸Can I see the SHA-256 fingerprint?

Yes. The viewer shows both the SHA-1 and SHA-256 fingerprints together with the public key algorithm and size.

▸How is a certificate viewer different from an SSL checker?

A checker connects to a live host to read the deployed certificate. A certificate viewer decodes a certificate you already have, such as one sent by your CA before installation.

Namecheap

Need a new SSL certificate?

DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.

Get SSL on Namecheap

Affiliate link — we may earn a commission at no extra cost to you.

More free tools

Certificate / Key Matcher

Check whether a private key and a certificate belong to the same key pair — computed locally, the key never leaves your browser.

PEM Viewer

Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.

SSL Format Converter

Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.

SSL Checker (A-F Grade)

Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.

SSL Bulk Checker

Check multiple SSL certificates at once

ACME Challenge Preflight

Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.

Let's Encrypt Checker

Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.

DNS Propagation Checker

Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.

LE Chain Compatibility

See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.

ACME Command Generator

Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.

Certificate Inspector

Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.

SSL Expiry Checker

Quickly check a domain's SSL certificate expiry date and remaining days.

Certificate Transparency Lookup

List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.

CAA Record Checker

Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.

Certificate Revocation Checker

Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.

SSL Handshake Tracer

Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.