How to use Certificate Inventory and Expiry Report
- Supply the public certificate pem collection and review time (utc) using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the certificate inventory report.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: Certificate Inventory and Expiry Report
Inventory a supplied collection of public certificates, group duplicate fingerprints and compare their validity dates with an entered review time.. This example uses synthetic public data.
Options
- Certificate collection
- Supply supported public PEM certificate blocks. The page inventories the supplied collection; it does not search your machine or contact a server.
- Review time
- Use an explicit UTC instant when reproducing a report. It is the time for the date comparison, not an observation of server operation.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
A validity window does not establish trust
Before, inside or after a certificate’s recorded date window describes its dates at your selected review time. It does not verify its issuer signature, a trust chain, hostname coverage or revocation. Duplicate fingerprints identify the same certificate bytes; certificates sharing a name may still differ.
Questions about Certificate Inventory and Expiry Report
Does inside the window mean trusted?
No. Date validity is separate from signature, chain, hostname and revocation checks.
How are duplicates grouped?
The report uses fingerprints of the supplied certificate bytes. Matching subject names alone are not duplicates.
Is a server contacted?
No. Only the supplied public certificates and review time are inspected.