viewhack

Certificate viewer: who it is for, who signed it, when it expires

Drop a certificate (.pem, .crt, .cer, DER or base64), a whole chain, a certificate signing request (CSR), a .p7b bundle or a password-protected .p12/.pfx file. You get the subject, issuer, expiry date with the days left, every name it covers, the key type and size, the fingerprints, and for a chain a real signature check of each link.

The file is read on your device. It is never uploaded, and a private key is never shown.

What it shows

Files it opens

FileWhat is insideHow it is recognised
.pem .crt .cer (text)certificates, keys or a CSR, base64 between BEGIN/END lines-----BEGIN CERTIFICATE-----, also after OpenSSL's "Bag Attributes" lines
.cer .crt .der (binary)one certificate in DER30 82 then the X.509 version field A0 03 02 01 02
.csr .reqa certificate signing request (PKCS#10)PEM CERTIFICATE REQUEST, or DER version 0, a name and a key
.p7b .p7ca certificate bundle (PKCS#7 / CMS signed data), as Windows exports chainsthe OID 1.2.840.113549.1.7.2
.p12 .pfxcertificates plus a private key, under a password (PKCS#12)DER version 3, then a PKCS#7 data OID
.keya private key: PKCS#8, PKCS#1, SEC1 or OpenSSHits BEGIN line, or its DER shape

Which .p12 and .pfx files open

A .p12 file encrypts its certificates and its key separately, often with different ciphers, and the choice depends on the program that wrote it. Before you type a password, the page lists each part's scheme and whether it opens here.

SchemeWritten byOpens here?
PBES2, PBKDF2 + AES-256-CBC, SHA-256 MACOpenSSL 3 by default, Windows "AES256-SHA256" export, Java keytoolyes (WebCrypto)
pbeWithSHAAnd3-KeyTripleDES-CBCWindows "TripleDES-SHA1" export; OpenSSL 1.x and many other tools for the key partyes (3DES written here)
pbeWithSHAAnd40BitRC2-CBCOpenSSL 1.x (and openssl pkcs12 -legacy) for the certificate partyes (RC2 written here)
128-bit RC2, 40- and 128-bit RC4, 2-key 3DESvery old toolsyes
PBES2 with AES-192-CBCraredepends on the browser: Chrome and Edge have no 192-bit AES
PBES1 with MD5 or MD2 (pbeWithMD5AndDES-CBC, pbeWithMD5AndRC2-CBC)very old Java and OpenSSLno: browsers have no MD5
GOST 28147-89, Kuznyechik, SM4, Camellia, scryptCryptoPro, Chinese national tools, some OpenSSL buildsno, named only
PBMAC1 integrity check (RFC 9579)OpenSSL 3.4 with -pbmac1_pbkdf2the contents open; the check is skipped and the page says so

The password is checked first against the file's integrity code (MAC), so a wrong password is reported as wrong rather than as a damaged file.

A worked example: Let's Encrypt's root

The file isrgrootx1.pem from letsencrypt.org/certs/ is 1,939 bytes. It opens as C=US, O=Internet Security Research Group, CN=ISRG Root X1, issued by itself, valid from 2015-06-04 11:04:38 UTC until 2035-06-04 11:04:38 UTC, with a 4096-bit RSA key, sha256WithRSAEncryption, key usage "Certificate signing, CRL signing", CA: yes with no path limit, and SHA-256 fingerprint 96:BC:EC:06:26:49:76:F3:74:60:77:9A:CF:28:C5:A7:CF:E8:A3:C0:AA:E1:1A:8F:FC:EE:05:C0:BD:DF:08:C6. Its self-signature verifies.

Put the intermediate r11.pem in front of it in one file and you get a two-link chain: R11 (C=US, O=Let's Encrypt, CN=R11, RSA 2048, valid until 2027-03-12 23:59:59 UTC, CA: yes, at most 0 more CA levels) names ISRG Root X1 as its issuer, the names match byte for byte, and R11's signature verifies with the root's key. That fingerprint is how you tell a real ISRG Root X1 from a look-alike with the same name: compare it with the one Let's Encrypt publishes.

What this cannot do