Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Convert certificate formats with OpenSSL

From Tech-Wiki


Convert X.509 certificates and related certificate bundles between common PEM, DER, PKCS#7 and PKCS#12 formats using OpenSSL.

ⓘ
Validation status
Reviewed against current OpenSSL 3.x command documentation on 27 September 2026. File extensions are conventions rather than a guarantee of encoding, so confirm the actual input format before conversion.
!
Protect private keys
PKCS#12 files and extracted private keys can contain sensitive private-key material. Avoid placing passwords directly on the command line where they may be exposed through shell history or process listings. Restrict permissions on any exported private-key files.

Common formats

  • PEM — Base64-encoded text commonly used for certificates and keys.
  • DER — Binary ASN.1 encoding often used for certificates.
  • PKCS#7 / P7B — Certificate and certificate-chain container; it does not contain the private key.
  • PKCS#12 / PFX / P12 — Container that can include a private key, certificate and additional certificates.

PEM to PKCS#12 / PFX

Create a PKCS#12 bundle containing a certificate, its private key and an optional chain.

>_Create a PKCS#12 bundle
openssl pkcs12 -export -in certificate.pem -inkey private-key.pem -certfile chain.pem -out bundle.p12

OpenSSL will prompt for the export password unless password options are supplied.

PKCS#12 / PFX to PEM

Extract the leaf certificate without the private key:

>_Extract the certificate
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out certificate.pem

Extract the private key while keeping the output key encrypted:

>_Extract an encrypted private key
openssl pkcs12 -in bundle.p12 -nocerts -out private-key.pem

If an application specifically requires an unencrypted private key, OpenSSL 3.x uses -noenc. Only use this where operationally necessary and protect the resulting file appropriately.

>_Extract an unencrypted private key
openssl pkcs12 -in bundle.p12 -nocerts -noenc -out private-key.pem
ⓘ
OpenSSL 3.x option change
The older -nodes option is deprecated in OpenSSL 3.x. Use -noenc when unencrypted private-key output is explicitly required.

PEM and DER

>_PEM certificate to DER
openssl x509 -in certificate.pem -outform DER -out certificate.der
>_DER certificate to PEM
openssl x509 -inform DER -in certificate.der -out certificate.pem

PKCS#7 / P7B

Extract certificates from a PEM-encoded PKCS#7 file:

>_PKCS#7 to PEM certificates
openssl pkcs7 -print_certs -in chain.p7b -out chain.pem

If the PKCS#7 input is DER encoded, add -inform DER.

Create a certificates-only PKCS#7 structure:

>_PEM certificates to PKCS#7
openssl crl2pkcs7 -nocrl -certfile certificate.pem -certfile chain.pem -out chain.p7b

Verify a certificate chain

Use openssl verify with an appropriate trusted CA file when checking a certificate chain.

>_Verify a certificate
openssl verify -CAfile trusted-ca.pem certificate.pem
✓
Inspect before converting
When a file extension is ambiguous, inspect the object first rather than assuming the encoding from .cer, .crt or another filename suffix.

Official references

See also