How to use PEM Certificate and CSR Decoder
- Paste one supported public certificate, CSR or public-key block.
- Read the decoded structure, algorithm, names and stored dates.
- Use a separate trust and signature workflow when you need to validate a certificate.
Example: PEM Certificate and CSR Decoder
Read the included public certificate’s metadata.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Validity dates are fields rather than a trust decision
A certificate can contain an apparently current date range and still be untrusted or revoked. This tool reads public DER structure; it does not verify the signature, chain, hostname, ownership or revocation status. A CSR similarly contains requested identity details, not an issued trusted certificate.
Extensions are only partially described
The output reports extension identifiers, critical flags and sizes rather than fully interpreting every extension. Do not treat an absent decoded name as proof that a restriction is absent. Private keys, trailing DER and unsupported structures are refused. Keep the report’s parsing scope separate from security-strength or compliance claims.
Questions about PEM Certificate and CSR Decoder
Does a valid date mean a certificate is trusted?
No. Trust also requires verified signatures, chain and other checks outside this tool.
Does a CSR prove the requested names belong to someone?
No. Names in a request are unverified input.
Can private-key PEM be decoded?
No. Paste only the supported public material.