What is an X.509 certificate?
X.509 is the standard format used for digital certificates in TLS, HTTPS, PKI, code signing, client authentication, email security, and many other cryptographic systems.
A certificate binds a public key to an identity. That identity may be a domain name, organization, person, device, or service. The certificate is normally signed by a Certificate Authority so other systems can verify that the certificate is trusted.
How to decode an X.509 certificate
The easiest method is to paste the PEM-encoded certificate into a certificate decoder.
- 1. Copy your certificate, including the BEGIN CERTIFICATE and END CERTIFICATE lines.
- 2. Open the Certificate Decoder.
- 3. Paste the certificate into the input field.
- 4. Decode the certificate and review its identity, validity, public key, fingerprints, and extensions.
What does a PEM certificate look like?
A PEM-encoded X.509 certificate normally looks like this:
-----BEGIN CERTIFICATE-----
MIID...
...certificate data...
-----END CERTIFICATE-----The Base64 text represents the DER-encoded certificate. A decoder converts that binary certificate structure into readable fields.
Important certificate fields to inspect
Subject
The subject identifies the entity the certificate was issued to. Older certificates may place the primary hostname in the Common Name field.
Issuer
The issuer identifies the Certificate Authority or intermediate CA that signed the certificate.
Subject Alternative Names
Subject Alternative Name, or SAN, lists the DNS names or other identities covered by the certificate. Modern TLS clients primarily use SAN entries when validating hostnames.
Validity period
The Not Before and Not After values indicate when the certificate becomes valid and when it expires.
Public key
The certificate contains the subject's public key, including the key algorithm and related parameters.
Fingerprints
Certificate fingerprints such as SHA-256 provide a compact identifier that can be used to compare certificates.
Signature algorithm
The signature algorithm tells you how the issuer signed the certificate.
Certificate decoding vs. checking a live SSL/TLS server
Decoding a certificate and testing a live TLS server solve different problems.
Certificate Decoder
Use it when you already have a certificate and want to inspect its contents.
SSL/TLS Checker
Use it when you want to connect to a live hostname and inspect the deployed certificate and TLS configuration.
To inspect a live server, use the SSL/TLS Checker.
Certificate vs. CSR
A Certificate Signing Request is not the same as a certificate. A CSR contains identity information and a public key that are submitted to a Certificate Authority when requesting a new certificate.
If your data starts with -----BEGIN CERTIFICATE REQUEST-----, use the CSR Decoder instead.
What is a certificate chain?
TLS certificates normally participate in a chain of trust. A typical chain contains:
- the leaf or server certificate
- one or more intermediate CA certificates
- a trusted root CA certificate
Use the Certificate Chain Builder when you need to understand how multiple certificates relate to one another.
Can you decode a certificate with OpenSSL?
Yes. If OpenSSL is installed, a PEM certificate can be inspected from the command line with:
openssl x509 -in certificate.pem -text -nooutA browser-based decoder is convenient when you want structured certificate information without installing or remembering command-line options.
Is it safe to paste a certificate into an online decoder?
Public certificates are designed to be distributed and normally do not contain private key material. However, you should always verify what type of data you are working with before submitting it anywhere.
Never paste a private key into a certificate decoder.
Private keys commonly begin with text such as BEGIN PRIVATE KEY, BEGIN RSA PRIVATE KEY, or BEGIN EC PRIVATE KEY.
Related certificate tools
Certificate Decoder
Decode X.509 certificates and inspect certificate fields.
Open tool →CSR Decoder
Decode PKCS#10 certificate signing requests.
Open tool →Certificate Chain Builder
Inspect certificate chains and trust relationships.
Open tool →SSL/TLS Checker
Inspect the certificate and TLS configuration of a live server.
Open tool →Decode an X.509 certificate now
Paste a PEM certificate into Security Toolbox to inspect its identity, issuer, validity, extensions, algorithms, public key, and fingerprints.
Open Certificate Decoder