TLS tools
Original utilities: CSR decoder, certificate decoder, expiry checker and DNS-01 lookup. These run in this application and do not send PEMs to a third party.
CSR decoder
Subject and public key from a PEM request.
Certificate decoder
Leaf and chain fields from PEM.
Expiry checker
Live 443 probe of a public hostname.
DNS-01 lookup
The TXT name ACME expects.
What these tools do
Decode a CSR or certificate PEM, inspect the live TLS certificate on a public hostname, and look up the _acme-challenge TXT name you must publish for DNS-01. Paste stays in this request. We do not store PEMs.
What they do not do
They are not a CA, a vulnerability scanner, or a substitute for staging ACME issuance. Private and loopback addresses are rejected.