Convert SSL Certificate Files: PEM, CRT, PFX Using OpenSSL

After receiving an SSL Certificate from a CA, the file format you receive may not match what your server or application requires. Apache needs PEM but you have PFX, or your Java application server requires JKS. This guide covers every OpenSSL command you need to convert SSL certificate files between all common formats.

Common SSL Certificate File Formats

Before converting, understand the differences between each format:

Tip: Check the current format first with openssl x509 -in cert.crt -text -noout. If it displays text successfully, it is PEM format. If not, try the DER commands.

SSL File Formats and Web Server Compatibility

Use this quick-reference table to determine which format you need for your target platform before deciding on a conversion path.

Web Server / Platform Supported Format Required Files
Apache (Linux) PEM .crt + .key + ca-bundle.crt
Nginx PEM .crt (fullchain) + .key
IIS (Windows Server) PFX .pfx with password
Tomcat (Java) JKS or PKCS#12 .jks or .p12
HAProxy PEM .pem containing key+cert+chain
DirectAdmin PEM Paste CRT and KEY text into UI
cPanel PEM Paste certificate text into UI
AWS ELB Load Balancer PEM Separate .pem for each component

PEM to PFX (for IIS / Windows)

Bundle the Certificate, Private Key, and CA Chain into a single PFX file:

openssl pkcs12 -export \
  -out certificate.pfx \
  -inkey privatekey.key \
  -in certificate.crt \
  -certfile ca-bundle.crt

You will be prompted for a password to protect the PFX file. Always set a strong password.

PFX to PEM (for Apache / Nginx)

Extract Certificate from PFX

openssl pkcs12 -in certificate.pfx -nokeys -out certificate.crt

Extract Private Key from PFX

openssl pkcs12 -in certificate.pfx -nocerts -nodes -out privatekey.key

Extract CA Chain from PFX

openssl pkcs12 -in certificate.pfx -cacerts -nokeys -out ca-bundle.crt

PEM to DER (for Java)

openssl x509 -outform der -in certificate.pem -out certificate.der

DER to PEM

openssl x509 -inform der -in certificate.der -out certificate.pem

PEM to P7B (for IIS)

openssl crl2pkcs7 -nocrl \
  -certfile certificate.crt \
  -certfile ca-bundle.crt \
  -out certificate.p7b

P7B to PEM

openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt

Create a PEM Bundle (Fullchain) for Nginx and HAProxy

Nginx and HAProxy require a PEM file that combines the Certificate, Intermediate CA, and Root CA into a single file — called a Fullchain Certificate. You must assemble this yourself from the individual files your CA provides.

Create Fullchain for Nginx

# Combine Certificate and CA Bundle into fullchain.pem
cat certificate.crt ca-bundle.crt > fullchain.pem

Reference the fullchain file in your Nginx configuration instead of the standalone certificate:

ssl_certificate /etc/ssl/fullchain.pem;
ssl_certificate_key /etc/ssl/privatekey.key;

Create PEM Bundle for HAProxy

HAProxy requires a single file containing everything, including the Private Key:

# Combine Private Key + Certificate + CA Chain into one bundle
cat privatekey.key certificate.crt ca-bundle.crt > haproxy-bundle.pem

Reference this bundle in your HAProxy configuration file:

bind *:443 ssl crt /etc/ssl/haproxy-bundle.pem

Important: The order inside a bundle file must be correct — Private Key first, then your own Certificate, then the Intermediate CA, then the Root CA. An incorrect order causes TLS handshake failures.

PEM to JKS (for Tomcat / Java)

Java uses Keytool instead of OpenSSL. You must convert via PFX first:

# Step 1: Create PFX first
openssl pkcs12 -export -out certificate.pfx \
  -inkey privatekey.key -in certificate.crt \
  -certfile ca-bundle.crt

# Step 2: Convert PFX to JKS using keytool
keytool -importkeystore \
  -srckeystore certificate.pfx \
  -srcstoretype PKCS12 \
  -destkeystore keystore.jks \
  -deststoretype JKS

Common Errors When Converting SSL Certificate Files

OpenSSL conversion can produce confusing error messages. The table below lists the most common errors with their causes and fixes.

Error Message Cause Fix
unable to load private key Key is encrypted or wrong format Use -nodes to decrypt, or check format with openssl rsa -in key.key -check
mac verify failure Wrong PFX password Verify the exact password, watch for spaces and special characters
no certificate matches Private Key does not match Certificate Compare MD5 modulus of both files — they must be identical
error reading input file Wrong file path or filename Verify the path, use an absolute path, or run the command from the directory containing the files
certificate is not self signed CA Chain is in wrong order Order certificates from Leaf → Intermediate → Root and verify the chain is complete

Remove a Passphrase from an Encrypted Private Key

If your Private Key was generated with a passphrase, most web servers require a decrypted version to start without manual password entry:

# Strip the passphrase from an encrypted Private Key
openssl rsa -in privatekey-encrypted.key \
  -out privatekey-decrypted.key

The command will prompt for the current passphrase. The output file will be a plain (unencrypted) key ready for use with Apache or Nginx without requiring a password at server startup.

Verify the Certificate Matches the Private Key

After conversion, verify the Private Key matches the Certificate:

# Check Certificate modulus
openssl x509 -noout -modulus -in certificate.crt | openssl md5

# Check Private Key modulus
openssl rsa -noout -modulus -in privatekey.key | openssl md5

# If both MD5 hashes are identical, they match correctly

Need Easy-to-Install SSL Certificates?

AsiaGB provides SSL Certificates from RapidSSL and GeoTrust with a Thai support team to help with installation and format conversion at no extra charge.

View SSL Certificates