Packetrove

Certificate Bundle Checker

Inspect a PEM certificate bundle, candidate issuer links, and evidence-based next steps.

Checked in your browser · Certificates and results remain in page memory

Certificate input

Only CERTIFICATE blocks and whitespace; up to 16 certificates and 48 KiB. Private keys are rejected.

0 / 49,152 bytes

ASCII DNS names only. Checks the selected leaf’s DNS SAN; no Common Name fallback.

Check results

Enter certificates and run a check. Editing input clears the previous result.

Understand these checks

Numbers show original input positions; JSON indices start at zero. Duplicate positions remain visible. Candidate names use conservative encoded comparison. An absent issuer is informational, and a failed candidate does not invalidate other links. Drafts stay in page memory across tool and language navigation; reloading clears them.

DNS SAN matching ignores ASCII case and a final hostname dot. A complete leftmost wildcard matches exactly one label. URLs, IP addresses, ports, wildcard inputs, and Unicode hostnames are rejected; convert internationalized names to punycode first. Common Name is displayed only, not used for identity checks.