WhyCrashed

Read any certificate — without handing it to a stranger's server.

Paste PEM or drop .cer / .crt / .pem / .der / .pfx / .csr / .key files. Expiry countdown, SANs, chain checks, hostname coverage and plain-English problem cards — decoded in your browser, never uploaded. That matters double for .pfx files, which contain your private key.

Drop certificate, key or CSR files here

.pem, .crt, .cer, .der, .pfx/.p12 (with password), .csr, .key — single certs or whole chains. Decoded in your browser; nothing is uploaded.

Choose file(s)

What you get

Instant status

Valid, expiring or expired — with exact day counts and a hostname-coverage checker including wildcard rules.

Chain intelligence

Drops a whole chain? We order it leaf→root, verify every link and flag missing intermediates — the classic "works in Chrome, fails in the app" cause.

Problems, explained

SHA-1 signatures, weak keys, self-signed certs, 398-day limits — every finding links to a plain-English fix page.

Browse the certificate field & problem reference →

Related tools