tool.ren

X.509 Certificate, CSR & Key Inspector

Inspect PEM or DER certificates, CSRs, public keys, and private-key structure locally. Review extensions, expiry, host names, CSR signatures, chains, and key matches.

Private by design
Certificate and CSR exports contain public material only. Private-key input is used only to derive a non-secret public-key match identifier inside the Worker.

Checks DNS SAN names, with CN fallback only when SAN is absent. Wildcards match one label.

This is a structural check, not a trust decision. Revocation, live CA policy, certificate transparency, and a trusted root store are not queried.

Up to 30 objects and 20 MB total. Password-protected PFX/P12 is not supported.

About X.509 Certificate, CSR & Key Inspector

Decode public-key objects and catch common deployment mistakes locally. Inspect PEM or DER certificates, CSRs, public keys, and private-key structure locally. Review extensions, expiry, host names, CSR signatures, chains, and key matches. The core workflow is designed to run in your current browser.

Key capabilities

  • Parse certificate, PKCS#10 CSR, SPKI, PKCS#8, PKCS#1, and SEC1 structures
  • Show SAN, key usage, constraints, identifiers, policies, AIA, and CRL indicators
  • Flag validity windows, weak signatures, small RSA keys, and hostname mismatch
  • Compare normalized public components without exporting private-key material

Useful for

  • Review a TLS certificate bundle before deployment
  • Verify a CSR signature and requested public key
  • Catch expiry, hostname, chain-link, and key-pair mistakes

Frequently asked questions

Is X.509 Certificate, CSR & Key Inspector free to use online?

Yes. X.509 Certificate, CSR & Key Inspector opens in a modern browser and does not require desktop software installation.

What is X.509 Certificate, CSR & Key Inspector useful for?

Common use cases include Review a TLS certificate bundle before deployment; Verify a CSR signature and requested public key.

Is my input or file uploaded?

The core processing workflow is designed to run locally in the browser. Key capabilities include Parse certificate, PKCS#10 CSR, SPKI, PKCS#8, PKCS#1, and SEC1 structures, Show SAN, key usage, constraints, identifiers, policies, AIA, and CRL indicators, Flag validity windows, weak signatures, small RSA keys, and hostname mismatch; account, comments, and anonymous analytics may still create normal site requests.

Comments

0 comments

Sign in to comment
AAccount

Sign in to comment and reply.

Sign in
No comments yet. Be the first to leave feedback.

ToolRen Online Toolkit © 2026