Certificate Inspector
Parse PEM certificates and inspect the TLS certificate chain of a host.
Debugging a TLS problem means reading subject names, expiry dates, SANs and the chain, which openssl output makes hard to scan. The Certificate Inspector in HackUtilities parses a PEM certificate you paste, or connects to a host and reads the certificate chain it serves. Pasted certificates are parsed on your machine, and live inspection connects only when you ask for it.
Parse pasted PEM
Paste a PEM certificate, even with surrounding text, to see subject, issuer, validity dates, days until expiry, serial number, version and signature algorithm.
Fingerprints and key info
Shows SHA-1 and SHA-256 fingerprints, plus the public key algorithm, key size and curve.
Extensions
Lists key usage, extended key usage, subject alternative names, basic constraints, CRL distribution points and authority info access when the certificate has them.
Live domain inspection
Enter a domain and port to read the full chain the server presents, along with the negotiated TLS protocol, cipher suite and key exchange group.
Validation warnings
Flags a domain mismatch, failed chain validation, an expired or not-yet-valid certificate, expiry within 30 days, SHA-1 signatures and RSA keys under 2048 bits.
Does parsing a certificate use the network?
No. The Parse Certificate tab decodes the PEM locally. Only the Domain Inspection tab opens a TLS connection, and only to the host you specify.
Can I inspect a server on a custom port?
Yes. Enter any port from 1 to 65535. The default is 443. Connections time out after 10 seconds.
Fetch a URL and grade its HTTP security headers with fix suggestions.
Open →Query DNS records with any resolver and run WHOIS lookups.
Open →MD5, SHA, BLAKE3 and CRC32 hashes and HMAC for text and files.
Open →No card, no account. Every tool included, bought once.