Convert certificate formats with OpenSSL
More actions
Convert X.509 certificates and related certificate bundles between common PEM, DER, PKCS#7 and PKCS#12 formats using OpenSSL.
Common formats
- PEM — Base64-encoded text commonly used for certificates and keys.
- DER — Binary ASN.1 encoding often used for certificates.
- PKCS#7 / P7B — Certificate and certificate-chain container; it does not contain the private key.
- PKCS#12 / PFX / P12 — Container that can include a private key, certificate and additional certificates.
PEM to PKCS#12 / PFX
Create a PKCS#12 bundle containing a certificate, its private key and an optional chain.
openssl pkcs12 -export -in certificate.pem -inkey private-key.pem -certfile chain.pem -out bundle.p12
OpenSSL will prompt for the export password unless password options are supplied.
PKCS#12 / PFX to PEM
Extract the leaf certificate without the private key:
openssl pkcs12 -in bundle.p12 -clcerts -nokeys -out certificate.pem
Extract the private key while keeping the output key encrypted:
openssl pkcs12 -in bundle.p12 -nocerts -out private-key.pem
If an application specifically requires an unencrypted private key, OpenSSL 3.x uses -noenc. Only use this where operationally necessary and protect the resulting file appropriately.
openssl pkcs12 -in bundle.p12 -nocerts -noenc -out private-key.pem
-nodes option is deprecated in OpenSSL 3.x. Use -noenc when unencrypted private-key output is explicitly required.PEM and DER
openssl x509 -in certificate.pem -outform DER -out certificate.der
openssl x509 -inform DER -in certificate.der -out certificate.pem
PKCS#7 / P7B
Extract certificates from a PEM-encoded PKCS#7 file:
openssl pkcs7 -print_certs -in chain.p7b -out chain.pem
If the PKCS#7 input is DER encoded, add -inform DER.
Create a certificates-only PKCS#7 structure:
openssl crl2pkcs7 -nocrl -certfile certificate.pem -certfile chain.pem -out chain.p7b
Verify a certificate chain
Use openssl verify with an appropriate trusted CA file when checking a certificate chain.
openssl verify -CAfile trusted-ca.pem certificate.pem
.cer, .crt or another filename suffix.