Pasting a production certificate into an arbitrary website creates an avoidable disclosure path. Public certificates are not secret in the same way as private keys, but they still expose names, internal conventions, issuers, validity windows, and operational context. Private keys and protected bundles must never be uploaded to an untrusted inspection service.
Open the file locally
CertView recognizes common certificate, chain, request, revocation, bundle, keystore, key, and JWK inputs. Open a certificate-like file in VS Code; for key and JWK files, keep the normal text editor as the default and choose CertView explicitly through Open With when you need the structured view.
Read identity before dates
- Subject describes the identity encoded in the certificate, but modern TLS hostname decisions normally depend on Subject Alternative Names.
- Issuer identifies the signer named by the certificate; it does not prove that your client trusts that issuer.
- Serial number distinguishes the certificate within the issuer's scope and is useful when correlating revocation or inventory records.
- Not Before and Not After define the encoded validity interval; compare them with the relevant system clock and renewal policy.
- Fingerprints identify the exact certificate bytes under a chosen digest and are useful for out-of-band comparison.
Cross-check with OpenSSL when needed
A second local tool is useful when investigating a parser difference or documenting a repeatable command-line check. OpenSSL provides focused commands for SANs, dates, subjects, issuers, serial numbers, and fingerprints.
openssl x509 -in cert.pem -noout -subject -issuer -serial -dates
openssl x509 -in cert.pem -noout -ext subjectAltName
openssl x509 -in cert.pem -noout -fingerprint -sha256Know what the result does not prove
Inspection is not RFC 5280 path validation, hostname verification, revocation checking, Certificate Transparency verification, WebPKI policy evaluation, FIPS certification, or organizational approval. CertView's lint findings are advisory. Use the actual client, trust store, policy engine, and revocation process for the decision you are making.