CSR Decoder

Decode a certificate signing request (CSR) to check its common name, organisation, SANs and key strength before ordering SSL.

How do I check what is inside a CSR?

Paste the CSR (it starts with -----BEGIN CERTIFICATE REQUEST-----) and the decoder shows the subject details — common name, organisation, city, state, country — the Subject Alternative Names and the key type and size, and checks it against certificate authority requirements.

Why decode before ordering

A typo in the domain or a weak key means the certificate has to be re-issued. Checking the CSR first confirms the exact domains, a two-letter country code and a key of at least RSA 2048 bits or ECDSA P-256.

Frequently asked questions

Is it safe to paste a CSR?

Yes, a CSR only contains your public key and details. Keep the private key secret.

Why is my SAN list empty?

Some CSRs only have a common name; most CAs then add the CN (and www) as SANs.

How do I create a CSR?

With openssl req -new -newkey rsa:2048 -nodes -keyout site.key -out site.csr, or from your hosting panel.