Certificate Inspector

Parse PEM certificates and inspect the TLS certificate chain of a host.

Uses network on request Native desktop macOS & Windows
Certificate Inspector
What it does

Debugging a TLS problem means reading subject names, expiry dates, SANs and the chain, which openssl output makes hard to scan. The Certificate Inspector in HackUtilities parses a PEM certificate you paste, or connects to a host and reads the certificate chain it serves. Pasted certificates are parsed on your machine, and live inspection connects only when you ask for it.

Parse pasted PEM

Paste a PEM certificate, even with surrounding text, to see subject, issuer, validity dates, days until expiry, serial number, version and signature algorithm.

Fingerprints and key info

Shows SHA-1 and SHA-256 fingerprints, plus the public key algorithm, key size and curve.

Extensions

Lists key usage, extended key usage, subject alternative names, basic constraints, CRL distribution points and authority info access when the certificate has them.

Live domain inspection

Enter a domain and port to read the full chain the server presents, along with the negotiated TLS protocol, cipher suite and key exchange group.

Validation warnings

Flags a domain mismatch, failed chain validation, an expired or not-yet-valid certificate, expiry within 30 days, SHA-1 signatures and RSA keys under 2048 bits.

FAQ

Does parsing a certificate use the network?

No. The Parse Certificate tab decodes the PEM locally. Only the Domain Inspection tab opens a TLS connection, and only to the host you specify.

Can I inspect a server on a custom port?

Yes. Enter any port from 1 to 65535. The default is 443. Connections time out after 10 seconds.

Pairs well with
All 46 tools →
Try Certificate Inspector free for 14 days

No card, no account. Every tool included, bought once.

Download