Certificate Lint
Analyze X.509 certificates for RFC 5280 compliance, CA/B Forum requirements, weak algorithms, key sizes, SAN configuration, extensions, and common PKI issues.
Certificate input
Paste or upload a PEM-encoded X.509 certificate.
Certificate analysis
Check certificate quality before deployment
Certificate linting helps identify configuration mistakes, standards violations, and security weaknesses that may cause interoperability or trust problems.
What the linter checks
Signature algorithms, key sizes, validity periods, Subject Alternative Names, Basic Constraints, Key Usage, Extended Key Usage, serial numbers, certificate versions, and other X.509 extensions.
What the linter does not do
Linting does not verify certificate chains, OCSP responses, CRLs, hostname validation, or browser trust decisions.
Guide
About X.509 Certificate Lint
Certificate linting detects structural, standards, and security issues before certificates are deployed.
This tool reviews common X.509 properties such as validity, algorithms, key sizes, names, extensions, and CA profiles.
Linting complements but does not replace chain validation, hostname verification, and revocation checking.
What the linter checks
Checks depend on the certificate profile and available fields.
- Validity periods
- Weak signature algorithms
- Key sizes and curves
- Subject Alternative Names
- Basic Constraints
- Key Usage and Extended Key Usage
Standards and best practices
Findings can reflect RFC 5280 requirements, CA/B Forum expectations, and common interoperability guidance.
Severity and context
Not every warning makes a certificate unusable. Review findings in the context of the intended environment and relying-party policy.
What linting does not do
The tool does not prove browser trust, contact OCSP responders, download CRLs, or verify a live server configuration.
FAQ
Frequently asked questions
What is certificate linting?
It is automated analysis of certificate structure, standards compliance, and common security mistakes.
Does linting verify trust?
No. Trust validation is a separate process involving chains and trust stores.
Can I lint self-signed certificates?
Yes. The findings should be interpreted according to the certificate's intended role.
Can it detect weak algorithms?
Yes. The linter can flag deprecated signatures or insufficient key sizes when detectable.
Does a clean report guarantee compatibility?
No. Client policies and application requirements can still differ.
Is the certificate uploaded?
Linting is intended to occur locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Chain Builder
Order X.509 certificates and generate fullchain.pem and chain.pem locally.
PKI & Certificates
SSL/TLS Checker
Inspect a live server's TLS protocol, cipher, certificate chain, expiration, and trust status.
Website Security
Certificate Transparency Inspector
Decode embedded Signed Certificate Timestamps from X.509 certificates.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates