STIR/SHAKEN Certificate Validator

Checks a certificate against the STI-GA SHAKEN Certificate Policy v1.4.2, RFC 8226 (STIR Certificates), and RFC 5280 (X.509) -- key algorithm, Key Usage, Basic Constraints, TNAuthList/SPC, CRL distribution point, DN naming, and validity period. Also checks the certificate against the STI-PA's current Trusted STI-CA root list and CRL -- the issuing chain up to a trusted root completes automatically once enough of it is provided to reach one.

1. Provide a certificate

Paste a PEM certificate below, or upload a .pem/.crt/.cer file. Include its issuing chain (in order after the leaf) to also check root trust -- the root itself doesn't need to be included, just enough of the chain to reach one already on the STI-PA's trust list; with only the leaf, just its own revocation status can be checked.

or

Fetches the URL the same way a carrier's verification service would -- HTTPS only, and also checks the TLS handshake, HTTP status, redirects, and response headers, not just the certificate content itself.