Generate TLSA Record

Generate DNS TLSA resource record from a certificate and given parameters.

Usage Field:
0 - PKIX-TA: Certificate Authority Constraint
1 - PKIX-EE: Service Certificate Constraint
2 - DANE-TA: Trust Anchor Assertion
3 - DANE-EE: Domain Issued Certificate

Selector Field:
0 - Cert: Use full certificate
1 - SPKI: Use subject public key

Matching-Type Field:
0 - Full: No Hash
1 - SHA-256: SHA-256 hash
2 - SHA-512: SHA-512 hash

Enter/paste PEM format X.509 certificate here:

Port Number: (e.g. 443)
Transport Protocol: (e.g. tcp, udp, sctp, dccp)
Domain Name:


Other DANE Tools


References