Confirming a certificate covers the hostnames you serve
Read the SAN list and check every name and wildcard you actually terminate. A missing subdomain here is the exact reason a browser shows a name-mismatch error.
Decodes a PEM TLS certificate and shows its details.
Decodes a PEM TLS certificate and shows its details.
-----BEGIN CERTIFICATE----- ...
Subject: CN=example.com Issuer: CN=R3 Valid: 2026-01-01 → 2027-01-01 SANs: example.com, www.example.com
Only the certificate metadata is shown — not any private key.
The fields describe who the cert is for, who issued it and when it expires.
Your input is sent to YAS infrastructure because the tool requires server-side processing or public network queries. Input is not stored.
curl -X POST "https://yas.sh/api/v1/tools/public-key-info" \
-H "Content-Type: application/json" \
-d '{"pem":"-----BEGIN CERTIFICATE-----\nMIIDPzCCAiegAwIBAgIUFROGZxKVcppGcj4z4zgwVLlXZsswDQYJKoZIhvcNAQEL\nBQAwLzEXMBUGA1UEAwwOZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFt\ncGxlMB4XDTI2MDgxNjA5NDIxNloXDTI3MDgxNjA5NDIxNlowLzEXMBUGA1UEAwwO\nZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFtcGxlMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0cup17jicv9ioKZcYH3eROjxX3RT3FYtceK+\nXoO70jMOJFS2gLomGHmrwB8S+4Efhws787dQj8AbhYdUkiKFSLxKXyIrXcAjSQ/J\nkfQjxW2HPbTRGeDp6rAACWXxKDKZOA8KqAzTd6v1nkFyW1KbOTCTtNGr4OHz7JBR\negQRUvUiuGJ5l1Wa/2yLEhl90T8QuhJH/JNYoR1RYay1LiN2lMeyZ1j19jOsH5Et\nw33DX25Od77j9G3rew/Up3EPus4o4uBbmod6b4wCFK0MVg+dL+SwwdqBvstvpJwj\nbcFVt14Iigeynd3+IbM6zcJ3XYGVByiDXyVEc9YXYAqA+e2DqwIDAQABo1MwUTAd\nBgNVHQ4EFgQUhi0sY1RjLsBQdUZjxd2rRvswGUowHwYDVR0jBBgwFoAUhi0sY1Rj\nLsBQdUZjxd2rRvswGUowDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOC\nAQEAQv81fsF3iER517ed0yNrhU8QeTgsFMtodWXauKbvBxBlmdOA/fv0Acl467qx\n04W5zLqFn5diDHHFvzol4HzVRZi0jV7Mr4LsqYXrEN8SJET/VCA8RJxj8WBoUkD+\ndtIlDR7ciLGKbU3l077Y11wiglMElWD9Ne+u5Q2wrA3EfkUP1dbapHn0buH5D/xt\nN1PDzS7funBvQ5wnupHhqDJATJqVa83RK99fNm7eUpegnP+rmVrOcVnQjDldlMNb\nbIFoHxpopEgLIcQpZaBhl6sKeKhxMWcxDhwVMsW+XZh4z+hFRisa70DxYykfOnEY\nFfabtY8iTCPoJQLrRB6brGtEFw==\n-----END CERTIFICATE-----"}'const res = await fetch("https://yas.sh/api/v1/tools/public-key-info", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
"pem": "-----BEGIN CERTIFICATE-----\nMIIDPzCCAiegAwIBAgIUFROGZxKVcppGcj4z4zgwVLlXZsswDQYJKoZIhvcNAQEL\nBQAwLzEXMBUGA1UEAwwOZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFt\ncGxlMB4XDTI2MDgxNjA5NDIxNloXDTI3MDgxNjA5NDIxNlowLzEXMBUGA1UEAwwO\nZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFtcGxlMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0cup17jicv9ioKZcYH3eROjxX3RT3FYtceK+\nXoO70jMOJFS2gLomGHmrwB8S+4Efhws787dQj8AbhYdUkiKFSLxKXyIrXcAjSQ/J\nkfQjxW2HPbTRGeDp6rAACWXxKDKZOA8KqAzTd6v1nkFyW1KbOTCTtNGr4OHz7JBR\negQRUvUiuGJ5l1Wa/2yLEhl90T8QuhJH/JNYoR1RYay1LiN2lMeyZ1j19jOsH5Et\nw33DX25Od77j9G3rew/Up3EPus4o4uBbmod6b4wCFK0MVg+dL+SwwdqBvstvpJwj\nbcFVt14Iigeynd3+IbM6zcJ3XYGVByiDXyVEc9YXYAqA+e2DqwIDAQABo1MwUTAd\nBgNVHQ4EFgQUhi0sY1RjLsBQdUZjxd2rRvswGUowHwYDVR0jBBgwFoAUhi0sY1Rj\nLsBQdUZjxd2rRvswGUowDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOC\nAQEAQv81fsF3iER517ed0yNrhU8QeTgsFMtodWXauKbvBxBlmdOA/fv0Acl467qx\n04W5zLqFn5diDHHFvzol4HzVRZi0jV7Mr4LsqYXrEN8SJET/VCA8RJxj8WBoUkD+\ndtIlDR7ciLGKbU3l077Y11wiglMElWD9Ne+u5Q2wrA3EfkUP1dbapHn0buH5D/xt\nN1PDzS7funBvQ5wnupHhqDJATJqVa83RK99fNm7eUpegnP+rmVrOcVnQjDldlMNb\nbIFoHxpopEgLIcQpZaBhl6sKeKhxMWcxDhwVMsW+XZh4z+hFRisa70DxYykfOnEY\nFfabtY8iTCPoJQLrRB6brGtEFw==\n-----END CERTIFICATE-----"
}),
});
const data = await res.json();import requests
r = requests.post("https://yas.sh/api/v1/tools/public-key-info", json={"pem":"-----BEGIN CERTIFICATE-----\nMIIDPzCCAiegAwIBAgIUFROGZxKVcppGcj4z4zgwVLlXZsswDQYJKoZIhvcNAQEL\nBQAwLzEXMBUGA1UEAwwOZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFt\ncGxlMB4XDTI2MDgxNjA5NDIxNloXDTI3MDgxNjA5NDIxNlowLzEXMBUGA1UEAwwO\nZXhhbXBsZS55YXMuc2gxFDASBgNVBAoMC1lBUyBFeGFtcGxlMIIBIjANBgkqhkiG\n9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0cup17jicv9ioKZcYH3eROjxX3RT3FYtceK+\nXoO70jMOJFS2gLomGHmrwB8S+4Efhws787dQj8AbhYdUkiKFSLxKXyIrXcAjSQ/J\nkfQjxW2HPbTRGeDp6rAACWXxKDKZOA8KqAzTd6v1nkFyW1KbOTCTtNGr4OHz7JBR\negQRUvUiuGJ5l1Wa/2yLEhl90T8QuhJH/JNYoR1RYay1LiN2lMeyZ1j19jOsH5Et\nw33DX25Od77j9G3rew/Up3EPus4o4uBbmod6b4wCFK0MVg+dL+SwwdqBvstvpJwj\nbcFVt14Iigeynd3+IbM6zcJ3XYGVByiDXyVEc9YXYAqA+e2DqwIDAQABo1MwUTAd\nBgNVHQ4EFgQUhi0sY1RjLsBQdUZjxd2rRvswGUowHwYDVR0jBBgwFoAUhi0sY1Rj\nLsBQdUZjxd2rRvswGUowDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOC\nAQEAQv81fsF3iER517ed0yNrhU8QeTgsFMtodWXauKbvBxBlmdOA/fv0Acl467qx\n04W5zLqFn5diDHHFvzol4HzVRZi0jV7Mr4LsqYXrEN8SJET/VCA8RJxj8WBoUkD+\ndtIlDR7ciLGKbU3l077Y11wiglMElWD9Ne+u5Q2wrA3EfkUP1dbapHn0buH5D/xt\nN1PDzS7funBvQ5wnupHhqDJATJqVa83RK99fNm7eUpegnP+rmVrOcVnQjDldlMNb\nbIFoHxpopEgLIcQpZaBhl6sKeKhxMWcxDhwVMsW+XZh4z+hFRisa70DxYykfOnEY\nFfabtY8iTCPoJQLrRB6brGtEFw==\n-----END CERTIFICATE-----"})
data = r.json()| Field | Type | Required | Description |
|---|---|---|---|
| pem | string | Yes | PEM-encoded certificate |
{ "subject": "CN=example.yas.sh", "issuer": "CN=example.yas.sh", "validFrom": "...", "validTo": "...", "fingerprint256": "..." }Decode a PEM X.509 TLS certificate.
400 VALIDATION_ERROR — invalid input or unsupported option.413 PAYLOAD_TOO_LARGE — input exceeds the 64 KB limit.429 RATE_LIMIT_EXCEEDED — rate limit exceeded (60 req/min).A PEM certificate is base64-encoded DER wrapped in BEGIN/END CERTIFICATE armor. Decoding it yields an X.509 structure containing the subject and issuer distinguished names, the validity window (notBefore/notAfter), the public key and its algorithm, the serial number, the signature algorithm, and extensions — Subject Alternative Names, key usage, extended key usage, basic constraints and CRL/OCSP endpoints.
Modern clients ignore the Common Name entirely and match hostnames against the Subject Alternative Name extension, per RFC 6125 and the CA/Browser Forum baseline requirements. A certificate whose CN is correct but whose SAN list omits the hostname will be rejected by every current browser, which is one of the most common causes of a certificate that 'looks right' but fails.
Read the SAN list and check every name and wildcard you actually terminate. A missing subdomain here is the exact reason a browser shows a name-mismatch error.
After a renewal, verify the validity window, the key algorithm and the chain position before deploying — not after users report an error.
Compare subject and issuer fields across the leaf and intermediates. If a leaf's issuer does not match the next certificate's subject exactly, the chain is misordered or incomplete.
Decoding each PEM gives expiry dates and key sizes for a fleet, which is how you find the 1024-bit key nobody remembers deploying.
What this tool deliberately does not do, and where it will disagree with other implementations.