CRL Distribution Point Inspector
Inspect an X.509 certificate and discover its CRL Distribution Point and Freshest CRL locations without contacting any external server.
Certificate input
Paste a certificate or upload a PEM, CRT, or CER file. Only the first certificate is inspected.
Revocation metadata
Find where certificate revocation lists are published
CRL Distribution Point and Freshest CRL extensions tell relying parties where certificate revocation information may be retrieved.
What this tool extracts
The inspector parses CRL Distribution Point and Freshest CRL extensions and lists the URLs embedded in the certificate.
What this tool does not do
It does not download CRLs, verify their signatures, or determine whether the certificate is currently revoked.
Guide
About CRL Distribution Point Inspector
Certificates can advertise Certificate Revocation List locations through CRL Distribution Point extensions.
This inspector extracts CRL and delta-CRL locations embedded in an X.509 certificate.
Extracting URLs does not determine whether the certificate is revoked; that requires retrieving and validating current revocation data.
What this tool extracts
The inspector parses CRL Distribution Points and Freshest CRL extensions and lists supported URI locations.
CRLs and delta CRLs
A CRL lists revoked certificates for an issuer. A delta CRL can contain changes since a base CRL.
Revocation validation requirements
A relying party must retrieve the appropriate CRL, verify its issuer signature, check freshness, and search for the certificate serial number.
Privacy and network behavior
This inspector analyzes certificate metadata without contacting the listed endpoints.
FAQ
Frequently asked questions
Does this tool check whether a certificate is revoked?
No. It only extracts CRL-related locations from the certificate.
What is a CRL Distribution Point?
It is an X.509 extension that tells clients where an issuer publishes revocation lists.
What is Freshest CRL?
Freshest CRL commonly points to delta CRLs containing updates since a base CRL.
Can a certificate have multiple CRL URLs?
Yes. Certificates can contain multiple distribution points.
Why might a CRL URL be unreachable?
The CA may have changed infrastructure, the network may block access, or the certificate may be obsolete.
Does the tool contact the URLs?
No. It only parses the locations embedded in the certificate.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
OCSP Checker
Inspect certificate OCSP responder metadata and revocation-check readiness.
PKI & Certificates
X.509 Certificate Decoder
Decode certificate identity, validity, algorithms, key details, and fingerprints locally.
PKI & Certificates
Certificate Lint
Check X.509 certificates for common RFC 5280, CA/B Forum, and security best-practice issues.
PKI & Certificates
Certificate Transparency Inspector
Decode embedded Signed Certificate Timestamps from X.509 certificates.
PKI & Certificates
CSR Decoder
Decode PKCS#10 certificate signing requests and review requested identities, keys, and extensions.
PKI & Certificates
Public & Private Key Analyzer
Identify PEM and OpenSSH key algorithms, formats, sizes, curves, and fingerprints locally.
PKI & Certificates