CSR Decoder
Paste any Certificate Signing Request to decode and inspect all fields — domain, organisation, key algorithm, key size, SANs and a security analysis.
Frequently Asked Questions
How do I read a CSR file?
A raw CSR file appears as Base64-encoded text between BEGIN CERTIFICATE REQUEST and END CERTIFICATE REQUEST headers — it is not human-readable in that form. Paste it into the CSR Decoder and it will extract and display all the contained fields in plain text.
What information is stored in a CSR?
A CSR contains the domain name (Common Name), organisation name and details, country and state, the public key to be included in the certificate, and any Subject Alternative Names for multi-domain certificates. It does not contain the private key.
Why should I check my CSR before submitting it?
Verifying your CSR before submission prevents costly delays. If the common name is misspelled, the organisation details are incorrect, or the key size does not meet the CA's requirements, you will need to regenerate the CSR — decoding first catches these errors immediately.
What is the difference between CSR Decoder and Check CSR?
Both decode CSR fields. CSR Decoder provides a more detailed security analysis including key strength assessment and SAN validation. Check CSR is a quick validity check. Use the decoder when auditing a CSR before submitting to a CA.
What key size should I use?
2048-bit RSA is the current minimum standard. 4096-bit provides stronger security at the cost of slightly slower handshakes. EC (Elliptic Curve) keys at 256-bit offer equivalent security to 3072-bit RSA with better performance.
Why are SAN entries important?
Modern browsers require Subject Alternative Names. A certificate with only a CN and no SAN entries will cause certificate errors in Chrome, Firefox and Edge even if the CN matches. Always include at least one SAN entry matching your domain.