STIR/SHAKEN Certificate Validator

Checks a certificate against the STI-GA SHAKEN Certificate Policy v1.4.2, RFC 8226 (STIR Certificates), and RFC 5280 (X.509) -- key algorithm, Key Usage, Basic Constraints, TNAuthList/SPC, CRL distribution point, DN naming, and validity period. Also checks the certificate against the STI-PA's current Trusted STI-CA root list and CRL, when a full chain is provided.

1. Provide a certificate

Paste a PEM certificate below, or upload a .pem/.crt/.cer file. Include its issuing chain (intermediate + root, in order after the leaf) to also check root trust -- without it, only the leaf's own revocation status can be checked.