Certificate / Key Matcher
All computation runs locally in your browser. Private keys and CSRs never leave your device, and we never collect or store them.
About Certificate / Key Matcher
The CSR.plus Key Matcher tells you whether a private key, a CSR, and an X.509 certificate belong to the same key pair. It compares the public-key modulus and exponent locally, so you can confirm which key was used to generate a CSR and to sign the corresponding certificate — without ever sending your private key anywhere.
Matching a key to a certificate is one of the most common SSL troubleshooting steps: it reveals whether you installed the correct key on your server, whether the CSR that generated your certificate was created with this key, and whether you kept the right key after a reissue or renewal. The check runs entirely in your browser.
Why use
- Confirm your private key matches the installed certificate before troubleshooting other issues
- Verify a CSR was generated from the key you still hold
- Detect mismatched key pairs after certificate reissue or server migration
- Works locally — the private key is never transmitted, logged, or stored
How to use
- Paste your private key (BEGIN PRIVATE KEY or BEGIN RSA PRIVATE KEY) into the first box.
- Paste the matching CSR and/or certificate into the other boxes — at least two inputs are required.
- Click the match button; the tool computes each public key locally and compares their moduli.
- Read the result: a match confirms all artifacts share one key pair; a mismatch identifies the odd one out.
Frequently asked questions
▸Is my private key safe?
Yes. All modulus and hash computations run in your browser; the private key is never transmitted or stored.
▸What does a "match" mean?
A match means the private key, CSR, and certificate all contain the same public key, so they belong to one key pair.
▸Can it verify a CSR against a certificate?
Yes. Paste the CSR and the issued certificate and the matcher will confirm whether they were generated from the same key.
▸Why would a key and certificate not match?
Common causes: you installed the wrong key file, the CSR was generated from a different key, or the key was regenerated during a reissue.
Namecheap
Need a new SSL certificate?
DV, OV, EV and wildcard certificates from just $5.98/yr — issued in minutes.
Affiliate link — we may earn a commission at no extra cost to you.
More free tools
Certificate Viewer
Paste or upload an X.509 certificate to inspect its subject, issuer, validity, key, fingerprints, SAN and extensions — all locally.
PEM Viewer
Paste a PEM bundle (certificates, keys, CSRs) and see a structured breakdown of every block — locally.
SSL Format Converter
Convert between PEM, PFX/PKCS#12 and P7B/PKCS#7 — all locally in your browser.
SSL Checker (A-F Grade)
Grade any domain from A to F: TLS versions, certificate health, chain trust and HSTS.
SSL Bulk Checker
Check multiple SSL certificates at once
ACME Challenge Preflight
Test HTTP-01 and DNS-01 validation before Let's Encrypt does: DNS, port 443, well-known reachability and TXT records with fix suggestions.
Let's Encrypt Checker
Detect Let's Encrypt certificates (R3/R10/E5/E6), see the 90-day renewal countdown, chain health and renewal advice.
DNS Propagation Checker
Check TXT, A, AAAA, NS and MX records across Cloudflare, Google and AdGuard resolvers and confirm propagation.
LE Chain Compatibility
See whether your site serves the new ISRG E5/E6 chain or the legacy cross-signed chain and whether old devices trust it.
ACME Command Generator
Generate copy-paste issuance commands for Certbot, acme.sh, lego and win-acme with HTTP-01 or DNS-01.
Certificate Inspector
Enter a domain to inspect certificate validity, expiry, TLS protocol and full chain integrity.
SSL Expiry Checker
Quickly check a domain's SSL certificate expiry date and remaining days.
Certificate Transparency Lookup
List every certificate ever issued for a domain in public CT logs — discover shadow and unauthorized certs.
CAA Record Checker
Query a domain's DNS CAA records to see which Certificate Authorities are allowed to issue certificates for it.
Certificate Revocation Checker
Verify whether a certificate has been revoked via its CRL distribution points, and view embedded OCSP endpoints.
SSL Handshake Tracer
Perform a real TLS handshake and record every step: DNS, TCP, negotiated TLS version and cipher, and each certificate returned.