SSL Certificate Information Tool - SimeonOnSecurity
NOTE: This tool runs entirely in your browser with client-side JavaScript. The certificate you paste is decoded locally and is never transmitted, logged, or stored.
HOW THIS WORKS: This tool does not connect to a server. A browser does not expose the TLS handshake
to JavaScript, so reading a certificate from a live host is not something a purely client-side page can do. Fetch
the certificate first with openssl s_client -connect host:443 -showcerts, then paste it here. Duplicating
that inside a browser would require sending your hostname to a server, which this site will not do.
Summary
| Paste a certificate and press Inspect. |
Subject Alternative Names
| Names appear here after inspection. |
Extensions
| Extensions appear here after inspection. |
What to Look At
- Validity dates. A certificate that expired last week is the most common cause of a handshake failure, and the only cause that fixes itself with a renewal.
- The hostname check. A name has to appear in the subjectAltName extension. The common name has not been accepted by browsers as a fallback for years, so a certificate with only a matching CN will still fail.
- The key and signature algorithms. SHA-1 signatures and RSA keys below 2048 bits are weak. A key of 4096 bits on a leaf is usually unnecessary rather than better.
- Basic constraints and key usage. An intermediate must have CA:TRUE and keyCertSign. A leaf with CA:TRUE is a misissuance.
- The fingerprints. Use these to compare against a known-good copy. Two certificates with the same subject differ if their serial or key differs.
Sponsored by The Cyber Sentinels Club
