./prontouso.com
BẢO MẬT & RIÊNG TƯ

Giải Mã Chứng Chỉ SSL/TLS X.509

Giải mã chứng chỉ bảo mật SSL/TLS định dạng PEM (.crt, .cer, .pem): kiểm tra đơn vị phát hành (Issuer), đối tượng được cấp (Subject), tên miền phụ (SANs) và ngày hết hạn.

Trạng thái công cụChạy trên trình duyệt của bạn
Xem trước
Or drop a certificate filehoặc chọn tệp từ máy
.pem, .crt, .cer · tối đa 2.0 MB. Xử lý trực tiếp trên trình duyệt, không bao giờ tải lên máy chủ.
Or drop a certificate filehoặc chọn tệp từ máy
.der, .cer, .crt · tối đa 2.0 MB. Xử lý trực tiếp trên trình duyệt, không bao giờ tải lên máy chủ.

This decodes certificate information only. It does not validate trust, hostname, DNS, revocation, or certificate chains.

Kết quả

This decodes certificate information only. It does not validate trust, hostname, DNS, revocation, or certificate chains.

Cách thức hoạt động

  1. Nhập dữ liệu của bạn

    Điền các giá trị cần thiết, dán văn bản hoặc tải lên tệp bạn muốn xử lý.

  2. Xem kết quả tức thì

    Hầu hết các công cụ cập nhật theo thời gian thực khi bạn nhập liệu; một số công cụ sử dụng một nút hành động duy nhất.

  3. Sử dụng kết quả

    Sao chép, tải xuống hoặc chia sẻ kết quả được tạo — bạn luôn có toàn quyền kiểm soát dữ liệu của mình.

Quyền riêng tư & xử lý dữ liệuChạy cục bộ 100% trên trình duyệt của bạn. Công cụ này không tải dữ liệu của bạn lên máy chủ.

Giải Mã Chứng Chỉ SSL/TLS X.509 là gì?

Paste or load a PEM/DER certificate to inspect its subject, issuer, validity period, public key, fingerprint, and common extensions.

TÌM HIỂU CÁCH HOẠT ĐỘNG CỦA CÔNG CỤ

How to read an X.509 certificate

Certificate information

The decoder reads fields encoded inside the certificate itself, such as Subject, Issuer, serial number, validity dates, Subject Alternative Names, Key Usage, and Basic Constraints.

Trust is different

A certificate can be decoded without proving that it is trusted for a domain. Trust requires hostname context, a certificate chain, revocation information, and platform trust roots, none of which this local decoder verifies.

Common uses

  • Check when a certificate expires.
  • Inspect SAN entries before configuring TLS.
  • Compare issuer and public key details during debugging.

What is parsed locally

Subject and issuer distinguished names, validity dates, serial number, public key details, common extensions, and the SHA-256 fingerprint are decoded from the certificate bytes.

Certificate parsing notes

PEM text or DER bytes are parsed in your browser to show certificate fields and a SHA-256 fingerprint; the tool does not validate a live TLS connection.

Các Câu Hỏi Thường Gặp (FAQ)

Does this prove a certificate is trusted?

No. It decodes certificate data but does not validate trust, hostname, DNS, revocation, or certificate chains.

Can I load DER certificates?

Yes, DER files can be loaded from your device and parsed locally when they are not malformed.

What is the SHA-256 fingerprint?

It is a digest of the certificate bytes, useful for comparing certificates without sharing the full certificate.

Why can an expired certificate still be decoded?

Decoding only reads the certificate bytes. Expiration affects whether a certificate should be trusted, not whether its fields can be parsed.

Công Cụ Liên Quan