แฮช/การเข้ารหัส
X.509 / SSL Certificate Decoder
แยกวิเคราะห์ใบรับรอง PEM (X.509/ASN.1 DER) — เรื่อง (subject), ผู้ออก, อายุการใช้งาน, คีย์สาธารณะ, ส่วนขยาย และลายนิ้วมือ
A PEM-format SSL/TLS certificate is essentially a text representation of a binary ASN.1 DER structure, unreadable without decoding. This tool breaks a certificate down into understandable fields: subject, issuer, validity period, public key, and fingerprints.
How to use it
- Paste a certificate in PEM format (starting with -----BEGIN CERTIFICATE-----) and it's parsed instantly.
- The result shows the subject (who it was issued to), the issuer (CA), the validity period, the public key's algorithm and size, extensions (SAN, key usage), and fingerprints (SHA-1, SHA-256).
- The Subject Alternative Names (SAN) list shows every domain the certificate is valid for.
Common uses
- Quickly checking a certificate's expiry date and the domains it covers without reaching for openssl in a terminal.
- Debugging HTTPS issues by checking a certificate's issuer, trust chain, or signature algorithm.
- Comparing a certificate's fingerprint against an expected value to verify authenticity.
Things to keep in mind
Parsing a certificate only shows its content — it doesn't verify the trust chain up to a root CA or check revocation status (CRL/OCSP); those need separate checks.
Modern certificates have short validity periods (90 days for Let's Encrypt) specifically to reduce the risk from a compromised key — that's expected practice, not a sign of a problem.
บทความเกี่ยวกับเครื่องมือนี้: X.509: ภายในใบรับรอง SSL มีอะไรบ้าง
คำถามที่พบบ่อย
ใบรับรอง X.509 มีข้อมูลอะไรอยู่จริง ๆ?
มันรวมคีย์สาธารณะเข้ากับรายละเอียดข้อมูลประจำตัว (subject, ผู้ออก, วันหมดอายุ) และลายเซ็นดิจิทัลจากผู้ออกใบรับรอง (หรือของตัวเองถ้าเซ็นรับรองตัวเอง) ทำให้ผู้อื่นตรวจสอบได้ว่าคีย์เป็นของใครและไม่ถูกดัดแปลง
ห่วงโซ่ใบรับรองกับใบรับรองปลายทางต่างกันอย่างไร?
ใบรับรองปลายทางระบุตัวเซิร์ฟเวอร์หรือหน่วยงานจริง ในขณะที่ห่วงโซ่ประกอบด้วยใบรับรองตัวกลางหนึ่งตัวขึ้นไปที่เชื่อมโยงกลับไปยัง root CA ที่เชื่อถือได้ — เบราว์เซอร์ต้องการห่วงโซ่ทั้งหมดเพื่อสร้างความเชื่อถือ ไม่ใช่แค่ใบรับรองปลายทาง
การถอดรหัสใบรับรองที่นี่อัปโหลดมันไปที่ไหนหรือไม่?
ไม่ การแยกวิเคราะห์และถอดรหัสทั้งหมดเกิดขึ้นในเบราว์เซอร์ของคุณ เนื้อหาใบรับรองจะไม่ออกจากอุปกรณ์ของคุณเลย
เมื่อใดที่ใบรับรองที่ลงนามด้วยตนเองถือว่าใช้ได้ปกติ?
สำหรับการทดสอบภายใน การพัฒนา หรือเครือข่ายปิด ซึ่งไม่จำเป็นต้องมีความน่าเชื่อถือสาธารณะจากเบราว์เซอร์ สำหรับเว็บไซต์สาธารณะ เบราว์เซอร์จะทำเครื่องหมายใบรับรองที่ลงนามด้วยตนเองว่าไม่น่าเชื่อถือ เนื่องจากห่วงโซ่ไม่นำไปสู่ CA รากใด ๆ
เหตุใดจึงจำกัดอายุการใช้งานของใบรับรอง?
อายุการใช้งานที่จำกัด (โดยทั่วไป 90 วันถึง 1 ปีสำหรับใบรับรองสมัยใหม่) ช่วยลดความเสี่ยงจากคีย์ส่วนตัวที่ถูกเจาะระบบ และบังคับให้มีการอัปเดตพารามิเตอร์เชิงรหัสลับให้สอดคล้องกับมาตรฐานความปลอดภัยล่าสุดอย่างสม่ำเสมอ