Certificates & PKI
All tools run client-side in your browser unless explicitly marked otherwise. No accounts, no cookies.
Certificate Decoder
Paste or drop a PEM/DER certificate and get the full X.509 breakdown: SANs, EKUs, key usage, thumbprints and expiry — without the certificate leaving your browser.
CSR Decoder & Validator
Decode a PKCS#10 certificate signing request and lint it for the problems that break Intune and EAP-TLS: missing SANs, missing UPN, weak keys.
Intune SCEP Profile Linter
Paste an exported Intune SCEP certificate profile (Graph JSON) and get it checked against the known pitfalls: UPN SAN, key size, EKU, renewal threshold and more.
Certificate Chain Builder
Paste certificates in any order — get them sorted leaf → intermediate → root, missing links identified, and a ready PEM bundle out.
server probeSCEP Endpoint Tester
Probe a SCEP/NDES endpoint's GetCACaps and see whether it advertises the capabilities modern clients need (SHA-256, AES, POST).