Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can read everything that matters in an X.509 certificate or a PKCS#10 certificate signing request (CSR) without running OpenSSL, and without uploading the file to a server you have not checked. Use a parser that runs locally, or a browser-based decoder whose code and behavior you have verified, and never give any decoder a private key. A decoder shows you what the file says. It does not tell you the certificate is trustworthy, and that distinction matters more than the choice of tool.

What a certificate and a CSR each contain

The two files look similar in a text editor, and people often mix them up. They do different jobs. A certificate is issued by a certificate authority (CA) and binds a public key to an identity. A CSR is a request: the applicant asks a CA to issue a certificate for a given subject and public key, and the CA decides what to sign.

An X.509 certificate, as defined in RFC 5280 (published May 2008), contains a TBSCertificate structure (the “to be signed” portion) plus a signature from the issuing CA. The CA’s signature is computed over the encoded TBSCertificate data, which is why changing any signed field invalidates the signature.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A PKCS#10 CSR, defined in RFC 2986 (published November 2000), carries a subject name, a public key, optional attributes, and a signature made with the matching private key. That signature proves the requester holds the private key for the public key in the request. It is not a signature from a CA, and a CSR is not a certificate.

Item X.509 certificate PKCS#10 CSR
Produced by A certificate authority The applicant, before any CA has acted
Subject Identity the CA issued the certificate for Requested subject name
Issuer Shown Not present; the CA fills this in when it issues
Validity interval Shown (not-before and not-after) Not present
Public key and algorithm Shown Shown
Signature algorithm Shown; signed by the CA Shown; signed by the requester’s private key
Extensions Often present (for example, subject alternative names) Optional; carried as request attributes or extensions
Private key Never included Never included

Two points follow from the table. First, a decoded CSR tells you what someone asked for, not what they were given. Second, neither file contains the private key. Microsoft Learn’s certificate documentation states the same thing: a certificate carries the subject’s public key, not the private key.

Step 1: Identify the input type before you parse it

Most textual certificates and requests use PEM armor, a Base64 body wrapped in a labeled boundary line. RFC 7468 specifies these textual encodings for PKIX, PKCS, and CMS structures. Read the first line before you paste anything:

  • Certificate: a boundary line beginning with the certificate label. Parse it with a certificate decoder.
  • CSR: a boundary line naming a certificate request. Use a CSR decoder, or a tool that accepts both and detects the type.
  • Private key: a boundary line containing “PRIVATE KEY” in any form. Stop here. Do not paste it into any decoder, online or offline, because a key is not something you need to read.

File extensions are a weak signal. A file named server.crt can hold a CSR, and a .pem file can hold anything. Trust the boundary label, and if the label is missing or unclear, check where the file came from before you go further.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Step 2: Decide where the parsing should happen

Decoders fall into three groups, and the data-exposure question depends on which group you pick.

Local command-line or desktop parser

The file never leaves your machine. This is the lowest-exposure option, and it is the right choice for production certificates, internal CA material, or anything you would not paste into a chat window. The trade-off is that you have to install and maintain the tool yourself.

Client-side browser decoder

The page loads, and parsing happens in your browser’s JavaScript engine. The input should never reach the site’s server. That property is not guaranteed by the fact that a tool runs in a browser, though. A page can still send input elsewhere through a script, an analytics call, or a server-side step. Check the network activity in your browser’s developer tools during a test with a non-sensitive certificate. If you see a request carrying the pasted text, the tool is not client-side in the way you need.

Remote hosted decoder

The file is sent to a server that parses it and returns the result. You cannot verify what that server logs, keeps, or forwards. Use hosted decoders only for public material that is already public, such as a certificate served on a public website.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

PKI Toolbox is one example of a decoder whose project documentation describes parsing entirely in the browser and offers a self-hosting option. That is a claim the project makes about its own software. It has not been independently audited, so treat it as a starting point for your own verification, not as proof about every deployment of it.

Step 3: Read a certificate field by field

When a decoder renders a certificate, check these items in roughly this order:

Rank #4
10 Packs Certificate Holders, Navy Blue Certificate Covers, Diploma Holders
  • PACKAGE CONTAINS: Set of 10 classic Navy Blue certificate holders to keep your certificate paper free of creases. Ideal protector and collector for your 8-1/2 x 11" size graduation, awards, presentations, diplomas, or letter size cardstock paper
  • SIZE: Certificate Holders measured 9.4 x12 inches after folded. Suit for holding vertically or horizontally 8.5" x 11" size documents, awards, certificates, and photos
  • STRUCTURE: Foldable certificate covers have semicircular cut grooves at four corners to hold the paper in place easily and securely and prevent slipping, which can protect your certificate perfectly and look more elegant
  • CLASSIC AND PROFESSIONAL LOOKING: Our Certificate Holders are Navy Blue and the front cover with ornate gold foil scroll design, making the certificate cover look official and easy to distinguish front and back
  • WIDE APPLICATION: Certificate covers were great for the presentation of awards and certificates! The ideal choice for schools, enterprises, organizations, Veterans Day, and churches to present awards and certificates
  • Subject and issuer: who the certificate names, and who signed it. A self-signed certificate has matching subject and issuer, but matching names alone do not prove self-signing.
  • Validity interval: the not-before and not-after dates. Read these in UTC where the decoder shows both local and UTC times.
  • Public-key algorithm and parameters: the key type (for example RSA or elliptic-curve) and its size or curve.
  • Signature algorithm: the algorithm the CA used to sign the TBSCertificate.
  • Extensions: subject alternative names (the hostnames or addresses the certificate covers), key usage, extended key usage, basic constraints (whether it can sign other certificates), and any others the decoder lists. RFC 5280 defines these fields and their meanings.

If a decoder shows a field it does not recognize, it should display the raw value rather than hide it. A parser that silently drops extensions gives you an incomplete picture.

Step 4: Read a CSR field by field

A CSR decoder should show:

  • Requested subject: the distinguished name the applicant wants in the certificate.
  • Public key and algorithm: the key the CA would bind to that subject.
  • Signature algorithm: the algorithm used for the request’s self-signature, which proves possession of the private key.
  • Requested attributes or extensions: for example, requested subject alternative names. These are requests, and the CA may change or refuse them.

When you review a CSR before sending it to a CA, compare the requested names against the names the service must answer for. A mismatch here is the most common reason a correctly formatted request produces a certificate that does not work for its intended hosts.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What decoding does not tell you

Reading fields is not the same as validating a certificate. A decoder that shows a valid-looking expiry date and a plausible subject has not established any of the following:

Best Value
Sale
Happy Secret Book-Style Diploma Cover 8.5" x 11", Smooth Leather Certificate Holder for Diplomas and Certificates
  • Designed for Standard 8.5" x 11" Documents: This diploma cover is designed to hold one standard 8.5" x 11" certificate or diploma and features a 4mm foam-padded core for support and a professional presentation.
  • Book-Style Opening with Clean Blank Front: This holder features a classic book-style opening and a plain front without printed text, creating a clean and professional look suitable for graduation, awards, and formal document presentation.
  • Smooth Leather-Look Exterior: Made with a smooth PU leather-look exterior, this certificate holder offers a classic appearance with a durable structure suitable for display, storage, and ceremony use.
  • Protective Interior Design: Four corner ribbons help hold the document in place, while the clear protective sheet provides added coverage against dust, fingerprints, and everyday handling.
  • Suitable for Individual and Bulk Orders: A practical choice for individual use, schools, training programs, award ceremonies, and corporate recognition events. Also suitable for bulk institutional purchases and custom logo applications.
  • that the issuer is a trusted CA, or that a complete chain from the certificate to a trusted root can be built;
  • that the certificate has not been revoked;
  • that the server presenting the certificate is configured to send it and its intermediates correctly;
  • that a CA will accept a given CSR, or what policy it will apply to the requested fields.

Those checks belong to validation, which a chain-aware client or a server-side test performs. A decoder that stops at field display does not do them. If a decoder labels a certificate “valid” or “trusted,” find out what check it ran, because the standards cited above define structure and do not promise that any particular tool performs full validation.

A privacy checklist before you paste anything

  • Confirm the boundary label is a certificate or certificate request, not a private key.
  • Use a local tool for any certificate tied to internal systems or production services.
  • If you use a browser decoder, test it with a throwaway certificate and watch the network activity for outbound requests.
  • Prefer a self-hosted copy of a tool you have read or reviewed, over an unknown public instance.
  • Delete pasted text from clipboard history and browser fields when you finish.

The point of this checklist is narrow. A certificate and a CSR contain public material, so the exposure risk is mostly about identifying internal hostnames and infrastructure, and about accidentally pasting something more sensitive. Treat any file that contains a private-key boundary as a secret, whatever its extension.

Taken together, the workable approach is simple: confirm the artifact type from its label, parse it where you can verify the data stays, and read the fields as a description of what was asked for or issued, not as proof that it is safe to use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources for the standards referenced above are RFC 5280 (certificate profile, published May 2008), RFC 2986 (PKCS#10 certification request syntax, published November 2000), RFC 7468 (textual encodings of PKIX, PKCS, and CMS structures), and the Microsoft Learn documentation on certificates. Project documentation for PKI Toolbox describes its own client-side parsing and self-hosting; its privacy statements are the project’s own.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.