CSR Viewer
FreeDecode a PEM-encoded Certificate Signing Request (PKCS#10): Subject, public key, signature algorithm, and Subject Alternative Names, then verify its self-signature is actually valid.
Runs entirely in your browser. Your CSR is never uploaded anywhere, not even for signature verification.
Recent Activity
Visible to everyone. Last 20 uses across all visitors, newest first.
Parsed a CSR and checked its self-signature.
1 hour ago
Parsed a CSR and checked its self-signature.
1 hour ago
Parsed a CSR and checked its self-signature.
1 hour ago
Parsed a CSR and checked its self-signature.
1 hour ago
Parsed a CSR and checked its self-signature.
1 hour ago
What this tool does
CSR Viewer decodes a PEM-encoded Certificate Signing Request (PKCS#10) and shows its Subject fields, public key details, signature algorithm, and Subject Alternative Names in plain text, then checks whether the CSR's self-signature is actually valid for the public key it contains.
How It Works
A CSR is a DER-encoded ASN.1 structure wrapped in PEM base64. This tool decodes that structure byte by byte: it reads each nested TLV (tag-length-value) element to walk down to the Subject distinguished name, the SubjectPublicKeyInfo block (RSA modulus and exponent, or EC curve and point), the optional extensionRequest attribute holding Subject Alternative Names, and the outer signature algorithm and signature bytes -- all client-side, with no server-side ASN.1 library involved.
To check the self-signature, the tool re-imports the CSR's own public key using the browser's Web Crypto API and asks it to verify the signature against the exact bytes of the CertificationRequestInfo block (everything the signature actually covers). For ECDSA signatures, the DER-encoded r/s values are first converted to the fixed-length raw format Web Crypto expects. A match means the person who holds the private key really did produce this exact CSR; a mismatch means it was altered or assembled incorrectly after signing.
Problems it solves
- Double-checking the Subject fields and Subject Alternative Names in a CSR before sending it to a Certificate Authority, without needing OpenSSL installed locally.
- Confirming a CSR you received from a colleague, client, or automated system is well-formed and genuinely self-signed before processing it further.
- Checking the key type and size (RSA 2048/4096-bit, or EC P-256/P-384/P-521) a CSR was generated with, to make sure it meets a CA's minimum requirements.
- Inspecting the raw ASN.1 structure of a CSR for debugging a certificate pipeline or learning how PKCS#10 is actually encoded.
Frequently asked questions
›Does this tool see my private key?
No. A CSR never contains your private key -- it only contains your public key, your identity details, and a signature made with the private key. This tool reads only what you paste, runs entirely in your browser, and never sends anything to a server, so there is nothing sensitive for it to leak even if you pasted a CSR by mistake.
›What does the "self-signature valid" check actually prove?
It proves the CSR was signed by whoever controls the private key matching the public key inside it -- in other words, the CSR has not been tampered with or corrupted since it was generated. It does NOT prove the Subject fields (company name, domain, etc.) are truthful; verifying identity is the Certificate Authority's job during issuance, not something a CSR can prove on its own.
›Why do some CSRs show "Could not verify (unsupported algorithm in this browser)"?
Browsers verify signatures using the Web Crypto API, which only supports a specific set of algorithms. This tool supports the common ones (RSA and ECDSA with SHA-1/256/384/512), but a CSR signed with an unusual or legacy algorithm outside that set cannot be verified client-side; its other fields still decode normally.
›Why does my CSR have no Subject Alternative Names?
SANs are optional in a CSR and only appear if they were explicitly requested when the CSR was generated (for example via openssl's -addext "subjectAltName=..." or a config file's [alt_names] section). Many CSRs, especially older or manually created ones, simply never had any SANs requested.
›What is the difference between a CSR and a certificate?
A CSR is a request you generate and send to a Certificate Authority (CA); it is never itself installed on a server. A certificate is what the CA sends back after verifying your identity -- it contains the same public key and Subject details as the CSR, plus the CA's own signature, a validity period, and a serial number.
Related Tools
Calculators
Amps To Watts Calculator
Convert between amps and watts for DC, AC single-phase, and AC three-phase circuits.
FreeCalculators
ANC Calculator
Calculate Absolute Neutrophil Count (ANC) from CBC values and see the NCI CTCAE neutropenia grade, right in your browser.
FreeCalculators
Angel Number Calculator
Discover the numerology meaning of a recurring number or your birth date Life Path Number, right in your browser.
FreeCalculators
Angle Converter
Convert angles between degrees, radians, gradians, turns, arcminutes, arcseconds, and milliradians with live DMS support.
Comments (0)
Found this tool useful? Leave a comment, share a tip, or tell us how we can make it better.
No comments yet. Be the first to share your thoughts!