Certificate Chain Inspector
Paste a leaf certificate and an explicitly chosen anchor, add any intermediates, or select local PEM/DER files. This browser tool builds a path and checks matching issuers, certificate signatures, validity at the selected time, CA and keyCertSign constraints, path length and critical extensions it can parse. It shows the certificate subjects, issuers and SHA-256 fingerprints and can download a JSON report. The result is an inspection relative to your supplied anchor; it is not a website or operating-system trust decision.
Key features
- Read PEM certificate text or local PEM/DER certificate files without uploading them
- Trace leaf through up to six supplied intermediates to an explicit anchor and verify each path signature
- Check the chosen reference time, CA constraints, keyCertSign and path-length limits
- Show subjects, issuers, serial numbers and SHA-256 fingerprints for the traced path
- Export a JSON report with the status, path and checks that were performed
How to use
- Paste or select the leaf certificate and the anchor you want to inspect against.
- Optionally provide intermediate certificates and set the reference date and time.
- Run the inspection and review the path status and per-certificate details.
- Download the JSON report if you need a record; check the stated validation limits before using it.
Use cases
- Diagnose a missing intermediate in a test TLS certificate bundle
- Compare a leaf certificate with a chosen private or test CA anchor
- Inspect whether a certificate was valid at a historical reference time
- Review certificate subjects and fingerprints before sharing a chain report
Frequently asked questions
Does a passing result mean a website is trusted by my browser?
No. The checks use only the anchor and certificates you supply. They do not check the browser or operating-system trust store, hostname, intended usage or policy.
Are revoked certificates detected?
No. This offline tool does not fetch or evaluate CRLs or OCSP responses. Revocation is always reported as not checked.
What if an intermediate certificate is missing?
The result identifies an incomplete issuer path. Add the issuing intermediate PEM or DER certificate and inspect again; a matching name alone is not enough without a valid signature.
Can I use DER as well as PEM?
Yes. Paste PEM blocks or select a PEM or DER file for each input. The intermediate field accepts a PEM bundle of up to six certificates.
Why must I provide an anchor?
The tool does not choose trusted roots for you. An explicit anchor makes the tested path and its limited conclusion clear.
Privacy
Certificate bytes are read only in this browser tab. The tool does not upload certificates or fetch revocation data. The downloaded report includes certificate names, serial numbers and fingerprints; review it before sharing.
Comments & questions