en

SSL Certificate Chain Tester - SimeonOnSecurity

NOTE: This tool runs entirely in your browser with client-side JavaScript. The certificates you paste are decoded and verified locally and are never transmitted, logged, or stored.

HOW THIS WORKS: This tool does not connect to a server. A browser does not expose the TLS handshake to JavaScript, so a purely client-side page cannot read a live chain. Get the chain first with openssl s_client -connect host:443 -showcerts, then paste it here. The certificates are ordered by matching each issuer to the next subject, and every signature is verified with the Web Crypto API, so a broken or forged link is detected rather than assumed.

Verdict

Paste a chain and press Test Chain.

Chain Order

The ordered chain appears here.

Link by Link

Each link between certificates is checked here.

Findings

Specific problems appear here.

What This Checks, and What It Cannot

  • Chain building. The tool works out the order by matching each certificate's issuer to the next certificate's subject, so you do not need to paste them in the right sequence.
  • Signature validity. Each link is verified cryptographically. A certificate whose signature does not match its issuer's key is reported, which catches a chain assembled from the wrong files.
  • Validity dates. Every certificate in the chain is checked against the current time, not just the leaf.
  • CA and key usage. An issuer must have CA:TRUE and keyCertSign, otherwise it is not permitted to sign certificates.
  • What it cannot do. It cannot check revocation, because that needs a CRL or OCSP request to a live server. It also cannot decide whether a root is trustworthy, since that depends on your trust store rather than anything in the certificate.

Sponsored by The Cyber Sentinels Club


FlockYou — ALPR and Flock Safety camera awareness devices from STS Collective
Shop Now — Save up to 20% Today Code: SIMEONONSECURITY