Security

CSR Decoder

Decode a PEM certificate signing request and read its subject, key algorithm and size, subject alternative names and requested extensions before you submit it to a certificate authority.

Last reviewed by the Radiatus Cloud team

Decoded request appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Check the request before the certificate arrives

A certificate signing request encodes the subject, the public key and the extensions you are asking a certificate authority to certify. Once issued, a certificate with the wrong hostnames or a key that is too small has to be revoked and reissued, which on a public CA means going through validation again and on an internal one means a change window. Reading the request takes ten seconds and catches the mistakes that would otherwise surface at deployment.

The subject alternative name extension is what matters

Browsers ignore the common name field entirely and validate only against subject alternative names. A request generated without the addext option or without a configuration file containing a v3_req section carries no SAN extension at all, and the resulting certificate fails in every current browser regardless of how correct the common name looks. This is by a wide margin the most common defect in a hand generated request, and it is invisible unless you decode the request and look.

Key size and algorithm are fixed at request time

The public key in the request is the key the certificate will certify, so an RSA 1024 key or a deprecated curve cannot be corrected by the CA. Public authorities reject RSA below 2048 outright. The signature on the request itself also matters: a request self signed with SHA-1 is rejected by many CAs even when the key is adequate, because the request signature is the only proof that the requester holds the private key.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why does my certificate work in curl but not in a browser?

Almost certainly no subject alternative names. curl and many command line tools still fall back to the common name; every current browser does not. Decode the request and confirm a SAN extension is present listing every hostname.

What key size should the request use?

RSA 2048 as a minimum, or ECDSA P-256, which is smaller and faster with equivalent strength. Public authorities reject RSA below 2048. RSA 4096 is slower to verify with little practical security gain over 2048 for a leaf certificate.

Can a CA change the details in my request?

Yes, and they routinely do. Most public authorities take only the public key and the subject alternative names and set everything else themselves, discarding the organisation and locality fields unless the validation level justifies them. The key and the names are what actually carry through.

Does decoding verify the request signature?

This tool parses the structure and reports the algorithms used. Full signature verification is done by openssl req -verify or by the CA. A request whose signature does not verify proves nothing about possession of the private key and is rejected.

Is my CSR sensitive?

A CSR contains only public information: the public key and the names you are requesting. It is not a secret. The private key that accompanies it is, and it never appears in the request.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste a PEM certificate signing request to decode its subject, key and extensions.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.