Certificate Chain Builder & Path Analyzer
Build and validate possible certificate paths from only the unordered X.509 certificates you supply.
Build certificate paths
Paste an unordered PEM certificate set. No AIA or remote source is fetched.
Did DecodeLens help?
Support the continued development of independent, browser-local developer tools.
About certificate path analysis
The builder uses only the supplied certificates and evaluates every locally proven issuer path.
Trust boundaries
- No AIA or other network source is fetched.
- Supplied trust anchors are explicit user choices, not OS or browser trust.
- Revocation, hostname, and application policy are not evaluated.
Related tools for this workflow
Continue with tools that decode, convert, inspect, or verify the same data.
- Security & identity
X.509 / PEM Certificate Decoder & Inspector
Inspect PEM or DER certificates, identity, validity, algorithms, SANs, extensions, fingerprints, and chain signatures.
Open tool - PKI & certificates
PKCS#7 / CMS Inspector
Inspect CMS and PKCS#7 content types, SignedData certificates and signers, EnvelopedData recipients, digest metadata, embedded content, and ASN.1 offsets.
Open tool - PKI & certificates
PKCS#12 / PFX Keystore Inspector
Verify PKCS#12 integrity, decrypt supported PFX/P12 safe contents, and inspect certificate, alias, localKeyId, key-presence, and protection metadata.
Open tool - PKI & certificates
.mobileprovision Inspector
Decode Apple provisioning profiles through CMS and plist layers; inspect App ID, team, expiration, device scope, entitlements, and developer certificates.
Open tool