DEV

SSL Certificate Checker

Paste a PEM certificate to read its validity dates, days left, issuer, covered hostnames, key type and fingerprints, decoded locally in your browser.

PASTE A PEM CERTIFICATE OR A WHOLE CHAIN (-----BEGIN CERTIFICATE-----)
The certificate is decoded in your browser and is never uploaded.

What this checker does

It reads an X.509 certificate and tells you what is in it: who it was issued to, who issued it, the dates it is valid between, how many days are left, the domain names it covers, the key type and the fingerprints. It also warns about the things that most often cause an outage, such as a certificate that has expired, one that is not yet valid, one that does not cover your hostname, or one that is signed with SHA-1.

Why you paste the certificate

A web page in a browser cannot open a connection to another server and read its certificate. Only the browser itself can, and it does not pass the details to scripts. Many online checkers get around this by connecting from their own server. This one decodes a certificate you paste, which means nothing about your certificate or domain is sent anywhere, and it works for internal, staging and not-yet-deployed certificates that a public checker could not reach.

How to get the certificate

With OpenSSL installed, this command prints the certificate a server presents. Replace example.com with your hostname and paste everything from the BEGIN line to the END line.

openssl s_client -connect example.com:443 -servername example.com -showcerts </dev/null

In Chrome or Firefox you can also click the padlock, open the certificate details and export it as PEM. Certificate files from your host or certificate authority, often ending in .crt or .pem, can be opened in a text editor and pasted directly.

What the results mean

Valid from / toThe window in which the certificate is accepted. Outside it, browsers show a full-page warning.
Subject alt namesThe hostnames the certificate covers. Browsers check these, not the common name.
IssuerThe authority that signed it. If issuer and subject match, the certificate is self-signed.
CA flagWhether the certificate may sign other certificates. A site certificate should say no.
FingerprintA hash of the certificate, used to confirm two copies are identical.

This tool does not check the signature against a trusted root, check revocation, or confirm that the server has the full chain installed. To look up the other half of a site's setup, try the DNS Lookup Tool, and for comparing fingerprints use the Hash Generator.

Frequently asked

Is my certificate uploaded anywhere?

No. The text you paste is decoded by JavaScript in your browser and is never sent to Curious Assistant or any other server.

Why can't this tool just check a domain name?

Browsers do not let a web page read the certificate from another site's connection. A domain checker has to run on a server. This page decodes a pasted certificate instead, so nothing leaves your device and it also works for private certificates.

Does it verify that the certificate is trusted?

No. It reports what the certificate says about itself. It does not validate the signature chain against trusted roots or check revocation. A certificate can look fine here and still be rejected by a browser if the chain is incomplete.

What does it mean if the hostname does not match?

Browsers compare the hostname you visit with the names in the subject alternative name list. If it is not covered, visitors see a name mismatch error. Wildcards such as *.example.com cover one level only, so they match www.example.com but not a.b.example.com.

How long are certificates valid for?

Public certificates are limited by the industry to about a year or less, and the maximum has been shrinking, so automated renewal is now standard. Check the days remaining and renew well before they run out.