WMW

CSR Viewer

Free

Decode a PEM-encoded Certificate Signing Request (PKCS#10): Subject, public key, signature algorithm, and Subject Alternative Names, then verify its self-signature is actually valid.

Runs entirely in your browser. Your CSR is never uploaded anywhere, not even for signature verification.

Recent Activity

Visible to everyone. Last 20 uses across all visitors, newest first.

Parsed a CSR and checked its self-signature.

1 hour ago

Parsed a CSR and checked its self-signature.

1 hour ago

Parsed a CSR and checked its self-signature.

1 hour ago

Parsed a CSR and checked its self-signature.

1 hour ago

Parsed a CSR and checked its self-signature.

1 hour ago

Comments (0)

Found this tool useful? Leave a comment, share a tip, or tell us how we can make it better.

Guest comments are reviewed before publishing. Sign in to post instantly.

No comments yet. Be the first to share your thoughts!

What this tool does

CSR Viewer decodes a PEM-encoded Certificate Signing Request (PKCS#10) and shows its Subject fields, public key details, signature algorithm, and Subject Alternative Names in plain text, then checks whether the CSR's self-signature is actually valid for the public key it contains.

How It Works

A CSR is a DER-encoded ASN.1 structure wrapped in PEM base64. This tool decodes that structure byte by byte: it reads each nested TLV (tag-length-value) element to walk down to the Subject distinguished name, the SubjectPublicKeyInfo block (RSA modulus and exponent, or EC curve and point), the optional extensionRequest attribute holding Subject Alternative Names, and the outer signature algorithm and signature bytes -- all client-side, with no server-side ASN.1 library involved.

To check the self-signature, the tool re-imports the CSR's own public key using the browser's Web Crypto API and asks it to verify the signature against the exact bytes of the CertificationRequestInfo block (everything the signature actually covers). For ECDSA signatures, the DER-encoded r/s values are first converted to the fixed-length raw format Web Crypto expects. A match means the person who holds the private key really did produce this exact CSR; a mismatch means it was altered or assembled incorrectly after signing.

Problems it solves

Frequently asked questions

›Does this tool see my private key?

No. A CSR never contains your private key -- it only contains your public key, your identity details, and a signature made with the private key. This tool reads only what you paste, runs entirely in your browser, and never sends anything to a server, so there is nothing sensitive for it to leak even if you pasted a CSR by mistake.

›What does the "self-signature valid" check actually prove?

It proves the CSR was signed by whoever controls the private key matching the public key inside it -- in other words, the CSR has not been tampered with or corrupted since it was generated. It does NOT prove the Subject fields (company name, domain, etc.) are truthful; verifying identity is the Certificate Authority's job during issuance, not something a CSR can prove on its own.

›Why do some CSRs show "Could not verify (unsupported algorithm in this browser)"?

Browsers verify signatures using the Web Crypto API, which only supports a specific set of algorithms. This tool supports the common ones (RSA and ECDSA with SHA-1/256/384/512), but a CSR signed with an unusual or legacy algorithm outside that set cannot be verified client-side; its other fields still decode normally.

›Why does my CSR have no Subject Alternative Names?

SANs are optional in a CSR and only appear if they were explicitly requested when the CSR was generated (for example via openssl's -addext "subjectAltName=..." or a config file's [alt_names] section). Many CSRs, especially older or manually created ones, simply never had any SANs requested.

›What is the difference between a CSR and a certificate?

A CSR is a request you generate and send to a Certificate Authority (CA); it is never itself installed on a server. A certificate is what the CA sends back after verifying your identity -- it contains the same public key and Subject details as the CSR, plus the CA's own signature, a validity period, and a serial number.

Related Tools