Certificate Lint

Analyze X.509 certificates for RFC 5280 compliance, CA/B Forum requirements, weak algorithms, key sizes, SAN configuration, extensions, and common PKI issues.

Browser onlyRFC 5280CA/B Forum

Certificate input

Paste or upload a PEM-encoded X.509 certificate.

Certificate analysis

Check certificate quality before deployment

Certificate linting helps identify configuration mistakes, standards violations, and security weaknesses that may cause interoperability or trust problems.

What the linter checks

Signature algorithms, key sizes, validity periods, Subject Alternative Names, Basic Constraints, Key Usage, Extended Key Usage, serial numbers, certificate versions, and other X.509 extensions.

What the linter does not do

Linting does not verify certificate chains, OCSP responses, CRLs, hostname validation, or browser trust decisions.

Guide

About X.509 Certificate Lint

Certificate linting detects structural, standards, and security issues before certificates are deployed.

This tool reviews common X.509 properties such as validity, algorithms, key sizes, names, extensions, and CA profiles.

Linting complements but does not replace chain validation, hostname verification, and revocation checking.

What the linter checks

Checks depend on the certificate profile and available fields.

  • Validity periods
  • Weak signature algorithms
  • Key sizes and curves
  • Subject Alternative Names
  • Basic Constraints
  • Key Usage and Extended Key Usage

Standards and best practices

Findings can reflect RFC 5280 requirements, CA/B Forum expectations, and common interoperability guidance.

Severity and context

Not every warning makes a certificate unusable. Review findings in the context of the intended environment and relying-party policy.

What linting does not do

The tool does not prove browser trust, contact OCSP responders, download CRLs, or verify a live server configuration.

FAQ

Frequently asked questions

What is certificate linting?

It is automated analysis of certificate structure, standards compliance, and common security mistakes.

Does linting verify trust?

No. Trust validation is a separate process involving chains and trust stores.

Can I lint self-signed certificates?

Yes. The findings should be interpreted according to the certificate's intended role.

Can it detect weak algorithms?

Yes. The linter can flag deprecated signatures or insufficient key sizes when detectable.

Does a clean report guarantee compatibility?

No. Client policies and application requirements can still differ.

Is the certificate uploaded?

Linting is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.