NOTE: This tool runs entirely in your browser with client-side JavaScript. The certificates you paste are
decoded and verified locally and are never transmitted, logged, or stored.
HOW THIS WORKS: This tool does not connect to a server. A browser does not expose the TLS handshake
to JavaScript, so a purely client-side page cannot read a live chain. Get the chain first with
openssl s_client -connect host:443 -showcerts, then paste it here. The certificates are ordered by
matching each issuer to the next subject, and every signature is verified with the Web Crypto API, so a
broken or forged link is detected rather than assumed.
Verdict
Paste a chain and press Test Chain.
Chain Order
The ordered chain appears here.
Link by Link
Each link between certificates is checked here.
Findings
Specific problems appear here.
What This Checks, and What It Cannot
Chain building. The tool works out the order by matching each certificate's issuer to the next certificate's subject, so you do not need to paste them in the right sequence.
Signature validity. Each link is verified cryptographically. A certificate whose signature does not match its issuer's key is reported, which catches a chain assembled from the wrong files.
Validity dates. Every certificate in the chain is checked against the current time, not just the leaf.
CA and key usage. An issuer must have CA:TRUE and keyCertSign, otherwise it is not permitted to sign certificates.
What it cannot do. It cannot check revocation, because that needs a CRL or OCSP request to a live server. It also cannot decide whether a root is trustworthy, since that depends on your trust store rather than anything in the certificate.