Why check a CSR
Before sending the request to a certificate authority, make sure the domains and organization details are correct: they cannot be changed in an issued certificate — you would have to issue a new one. The decoder shows the contents of the request exactly as the certificate authority will see it.
What we show
- Common Name and SAN — all the domains the certificate will be valid for.
- Organization, city, country — important for OV and EV certificates.
- Key — algorithm and length; certificate authorities do not accept RSA keys shorter than 2048 bits.
The tool also decodes issued certificates: paste the contents of a .crt or .pem file to see the issuer, validity dates and fingerprint. There is no need to paste a private key here. No CSR? Create one with the CSR generator.